Skip to main content
Gypsy_Dave
New Member
May 6, 2020
Question

Help with access to remote site tunnel VLAN

  • May 6, 2020
  • 9 replies
  • 7396 views

Hi guys,

I have a remote site connection setup from home to the office via two FG's. Home has FG30D, Office FG80E.

 

The office has two VLANS. VALN1 and VLAN2 but I can only access VLAN1 and not VLAN2.

 

I've checked the rules on the office FG and I have the following policy setup on the office FG.

Incoming interface: Tunnel interface

Outgoing is: LAN interface

Source: is my home IP subnet

destination: VLAN1 and VLAN2 ( entries are created on ANY interface)

 

I've also tried adding another rule which allows Tunnel interface to VLAN2 interface. Still not luck reaching VLAN2.

 

Any ideas?

Thanks.

 

 

    9 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    May 6, 2020

    Likely the second phase2/selector is not up. Check with CLI "get vpn ipsec tun sum". Looke for "selectors(total,up): 2/?" If both are up it should be "2/2". My guess is you got only "2/1". Then troubleshoot why the second one doesn't come up.

    Dave_Hall
    New Member
    May 6, 2020

    Is there a route to VLAN2?

    sw2090
    SuperUser
    SuperUser
    May 7, 2020

    II think your outgoiing interface is wrong.

     

    On a FGT each vlan is a virtual interface. So at office FGTyou have to have a policy that has those as outgoing interface.

    Also you have to have a corresponding policy on tjhe home fgt:

    incoming iface: the port where yourhome lan is

    outgoing iface: the tunnel to office

    source: your home lan

    destination: vlan1 and vlan2 subnets

     

    Additionally the home FGT must have a static route for each vlan subnet you need to access at office!

    Gypsy_Dave
    New Member
    May 8, 2020

    Right guys cracked it. Many thanks for all your help. The problem was I was going crazy as there was actually two different tunnels setup.

     

    So I concentrated on the HOME to WORK tunnel only and found the IP policy on the work FG, from home tunnel interface to VLAN2 did not have the destination marked as ALL. The interfaces were good but destination was marked as only VLAN2. I changed this to all and I now have access two this vlan from home.

     

    Cheers,

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!