Skip to main content
Eugene_Alaska
New Member
July 24, 2023
Question

Can remote FortiClient user get access to local lan connected over syte-2-syte tunnel?

  • July 24, 2023
  • 4 replies
  • 2243 views

Hello.

1234.png

See picture, please. 
Users from LAN-1 access LAN-2 without any problem over syte-2-syte ipsec tunnel.

Also Users from LAN-2 access LAN-1 over syte-2-syte ipsec tunnel.

Question.
Can the remote FortiClient user access internal network 2?
If so, how?

Now access only to network 1.

 

Thanks.

 

P.S.

Fortigate1 is FortiGate-61E model.
Fortigate2 is FortiGate-61E model also.

4 replies

kjohri
Staff
Staff
July 24, 2023

Hello,

Yes, SSL VPN users will be able to access the resources across Site to Site tunnel. Please refer to the below article-
https://docs.fortinet.com/document/fortigate/7.2.5/administration-guide/45836

Eugene_Alaska
New Member
July 24, 2023

@kjohri wrote:

Hello,
Yes, SSL VPN users will be able to access the resources across Site to Site tunnel.

But remote users use ipsec vpn to connect.
Or does it not matter?

 

nithincs
Staff & Editor
Staff & Editor
July 24, 2023

yes, you could achieve it. Make sure to add dailup tunnel subnet in phase2 selector of the site-site tunnel.

in FGT1 source :10.5.41.0/24 dest :192.168.8.0/24
in FGT2 source 192.168.8.0 dest :10.5.41.0/24

In FGT2, add a routeto 10.5.41.0 via tunnel interface.

Make sure to have the policies in place at both the firewall.

With this it should work

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!