Access site behind Site-to-Site tunnel via. L2TP Remote Access (Windows Native)
We recently started testing replacing our current firewall (Endian) with a Fortigate as a our HQ main firewall.
We successfully set-up a Site-to-Site IPSEC tunnel to one of our branches (branch still using an Endian firewall) on the Fortigate.
Afterwards we set-up a L2TP Remote Access tunnel (Windows Native) to the Fortigate.
Both the Site-to-Site and L2TP tunnel work perfectly.
But, when connecting to the HQ Fortigate via. L2TP we cannot reach the branch which is connected via site-to-site.
We haven't yet found a working combination of firewall policies and static routes to allow the L2TP tunnel client to access the firewall behind the site-to-site.
How would we best go about this and what might we have missed?
