Question
Address translation to IPsec VPN
Hi all. New member here and fairly new to the forti world so please bare with me if im missing something obvious :) I have a fortigate 60C in my office and one offsite for remote access. I have IPsec VPN set up between them and working splendid. Now to my trouble, we had to add a bunch of machines on my office that is on the same subnet as the offsite network... My idea was to get a " new sub net" internally and have that translated the offsite sub net just before entering the tunnel. So what i did was to add a new Virtual IP with the settings: External Interface: internal External IP Address/Range: my " new sub net" Mapped IP Address/Range: Offsite sub net I then went to the policy that before allowed connection from my internal net to offsite VPN and changed Destination Address to my new Virtual IP.. The effects, i can now connect to my offsite machines with both sub net addresses... What am i missing out here. i obviously want the " old sub net" to stay at my office and i can' t find anywhere any allowance for the " old sub net" to my tunnel... Im continuing to study the manual and if any of you have a nice pointer or advice it is highly appreciated.