Re: Cascaded VPN
☼ Best Answerby Celio 2020/03/25 09:15:22
Make sure the remote FGT knows your source LAN address space. It needs a static route for this.
Suppose your FC has IP 10.2.3.4. Your local FGT will know about that range, otherwise you couldn't surf the LAN. The remote FGT, receiving traffic from 10.2.3.4, drops it as "unknown". So create a static route, destination "10.2.3.0/24", gateway address (none), interface site-to-site-tunnel.
Second prerequisite is that the tunnel will carry that traffic as well. Have a look at the s2s-phase2 Quickmode selectors. Between FGTs, you may use the wildcard '0.0.0.0/0', thus permitting any traffic to open tunnel negotiations.
If 10.2.3.0/24 is missing in phase2, either add another phase2, or switch to wildcard addressing. This needs to be done on both sides of the s2s-tunnel.
Ede " Kernel panic: Aiee, killing interrupt handler!"