Hot!How to setting manage all internet access through HQ site

Author
hmtung
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/05/19 21:30:51
  • Status: offline
2019/05/19 21:38:03 (permalink)
0

How to setting manage all internet access through HQ site

Hi all 
 
I have 04 site vpn ipsec to HQ , vpn site to site its ok, however I need 
all sites access internet back through by HQ WAN how to do pleas help me
 
 
Thank you so much
 

Attached Image(s)

#1

3 Replies Related Threads

    ede_pfau
    Expert Member
    • Total Posts : 6019
    • Scores: 480
    • Reward points: 0
    • Joined: 2004/03/09 01:20:18
    • Location: Heidelberg, Germany
    • Status: offline
    Re: How to setting manage all internet access through HQ site 2019/05/20 01:26:30 (permalink)
    0
    hi,
     
    two steps on each branch FGT (FAC1-4):
    1- set a static route to the public IP of HQ pointing to the WAN port ("wan1", gateway=ISP router). Use a host route, for example "91.66.43.124/32".
    2- set the static default route "0.0.0.0/0" pointing to the tunnel interface (no gateway), not to WAN anymore.
     
    The first route will ensure that the branch FGT can establish the VPN tunnel. The second route directs all traffic to the HQ FGT.
     
    On the HQ FGT:
    3- create one or more policies to allow branch traffic to the internet (tunnel to WAN, subnet_FAC1 to all). Enable NAT on these!
     

    Ede

    " Kernel panic: Aiee, killing interrupt handler!"
    #2
    Toshi Esumi
    Expert Member
    • Total Posts : 1622
    • Scores: 137
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: How to setting manage all internet access through HQ site 2019/05/20 09:49:37 (permalink)
    0
    Just don't forget to adjust the phase2 network selectors appropreately like [0/0<->local subnets] or back to the default [0/0<->0/0] if you have configured specific ones already.
    #3
    Cleyton
    New Member
    • Total Posts : 16
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/02/08 08:46:36
    • Status: offline
    Re: How to setting manage all internet access through HQ site 2019/07/12 09:15:31 (permalink)
    0
    Hello hmtung
    I'm having the same problem, I have several branches with 50E fortigate and in the HQ a 80E fortigate, I want branch internet traffic to go through the VPN tunnel and exit through the WAN of the HQ.
    Did you solve this problem?
    #4
    Jump to:
    © 2019 APG vNext Commercial Version 5.5