Skip to main content
Westcana
New Member
March 11, 2020
Question

How to WiFi at branch office route across tunnel to head office?

  • March 11, 2020
  • 3 replies
  • 7810 views

I have a branch office that has a point to point vpn with the head office. This link has been operating flawlessly for months now. Clients on either end can communicate with clients on the other end. There is no nat between the sites. Each branch office has it's own subnet. The branch offices are using Fortigate 50E and the head office is using Fortigate 60E. The branch office Fortigates are the type that have build in WiFi, so the fortigate is aware of the subnet for the wifi and acts at the gateway/dhcp/dns for the wifi network. The branch offices have a private wifi that is on it's own unique subnet that is able to reach the wired subnet at it's own branch. However I am unable to have that private wifi reach the head office subnet. There is no nat between the private wifi and the wired network.

 

    3 replies

    brycemd
    New Member
    March 11, 2020

    There are 3 parts to getting this done:

     

    1. Routing - Do the firewalls have a route to get to the wifi network via tunnel

    2. ipv4 policy - Is the traffic allowed based on firewall rules interface/source/destination

    3. Phase 2 selectors - Does the traffic match the VPN tunnels phase 2

    brycemd
    New Member
    March 11, 2020

    There are 3 parts to getting this done:

     

    1. Routing - Do the firewalls have a route to get to the wifi network via tunnel

    2. ipv4 policy - Is the traffic allowed based on firewall rules interface/source/destination

    3. Phase 2 selectors - Does the traffic match the VPN tunnels phase 2

    brycemd
    New Member
    March 11, 2020

    There are 3 parts to getting this done:

     

    1. Routing - Do the firewalls have a route to get to the wifi network via tunnel

    2. ipv4 policy - Is the traffic allowed based on firewall rules interface/source/destination

    3. Phase 2 selectors - Does the traffic match the VPN tunnels phase 2

    rwpatterson
    New Member
    March 11, 2020

    If the VPN on the remote firewall is set up in policy mode, you'll have to break it and recreate it in interface mode. When that is done, you can assign a route for that traffic to get it away from the default route out the door.

    Westcana
    WestcanaAuthor
    New Member
    March 11, 2020

    1. I would have assumed that the tunnel (having been setup using the vpn wizard) would automaticly include the remote sites subnets. Certainly that worked for the wired networks. That being said, I did create static routes but didn't see any change. 2. Policies are in place allowing the traffic

     

    So that would be to change the Phase 2 selectors local and remote address's to subnet instead of named address? Can I just add a subnet instead of changing the existing settings?