Skip to main content
generaltab
New Member
April 2, 2020
Question

How to allow access between remote IPSec endpoints?

  • April 2, 2020
  • 4 replies
  • 8305 views

Greetings,

 

I have a FortiGate at the main office, subnet 192.168.1.0

There are several hardware-based IPSec VPNs for remote locations:

Remote office 2, subnet 192.168.2.0

Remote office 3, subnet 192.168.3.0

Remote office 4, subnet 192.168.4.0

and so on.

The main office can reach each of the remote offices.

How can I allow each of the remote offices to reach each other?

 

Thank you,

 

Steve

4 replies

rgesche
New Member
April 2, 2020

two options:

option one: you configure in any office ipsec connections to any office

option two: add all subnets in  ipsec phase 2 options of ipsec configuration for any tunnel, create routing entries in remote offices for destionation subnets (other rekote offices) over ipsec inteface and corresponding firewall rules on all fortigates.

 

generaltab
New Member
April 2, 2020

Thanks. Does anyone know of a guide for accomplishing this?

rgesche
New Member
April 2, 2020
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.