Skip to main content
Fergieml
New Member
April 24, 2020
Question

how to route between vpns

  • April 24, 2020
  • 12 replies
  • 14031 views

I have Fortinet 30e with 1 WAN interface.

I have 2 x site 2 site vpn tunnels, say VPNA 10.87.125.0 and VPNB 172.16.14.0

Internal LAN is say 10.3.4.0

I want to have traffic coming into VPNA to route out to VPNB and VPNB to route to VPNA

 

What is the best way to do this?

Create VLAN 10.3.5.0 do VIP for each VPN and then do static route?

See picture for drawing

 

    12 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    April 24, 2020
    Fergieml
    FergiemlAuthor
    New Member
    April 24, 2020

    I looked at this last night but was worried because all the spokes in the doc are on the same subnet (10.1.0.0/16) which is not the case in my example. Also I have no control over the spoke routers other than to advise the downstream staff to add routing.

    Can it be as simple as adding IP pool (with either NAT pool or PAT) on WAN router, and then create a policy that picks up anything from VLANB and route to VLANA?

    Thanks for your help

     

    Toshi_Esumi
    SuperUser
    SuperUser
    April 25, 2020

    No. They are all /24s and completely different subnets, just happen to have same 10.1 for the first 16bits.

    You have to make the change on the spoke side. Otherwise how can the remote side FGT can know where to route the packet to if the dst IP is in the other side of remote? It wouldn't break anything since it currently doesn't route at all anyway. Nothing to lose.

    katesmith1304
    New Member
    April 28, 2020

    well the information is very helpful . i will share the link in my group. i like almost every question answered on this forum in such concise and precise manner

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!