Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Cornelis
New Contributor

IPsec site to site routing traffic

Hi All

 

I am pretty new to fortinet products and was hoping that someone could guide me in the right direction.

 

I have 2 fortigates where i have created a site to site vpn. The tunnel is up between hq and remote office. I need to route all traffic from a vlan from remote office to hq, so bassicaly the remote vlan has the same public IP as HQ.

 

Many thanks in advance

 

 

3 REPLIES 3
ede_pfau
SuperUser
SuperUser

What? remote and HQ have the same public IP? Could you please clarify?


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Cornelis

Sorry, they have different IP's, i need the vlan from remote office to route through gateway of HQ so it looks like the remote machine is sitting in HQ 

 

 

sw2090
Honored Contributor

Well in this case your remote office GT will have to have a static route toa subnet at HQ used for this. This oute must go over the IPSec Tunnel.

Then you would need a policy that comes after your outher policy on remote Site FGT (but before Policy 0) which will alllow traffic from client subnet to everywhere via the IPSec Tunnel.

HQ FGT will then need a static route to remote client subnet over the IPSec Tunnel plus a Policy that allows traffic coming from the Tunnel with remote subnet as source and internet Port(s) or SDWAN as destination with NAT enabled.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors