Hub and Spoke - I don´t get it
Hi everybody,
I have big problems in understanding hub and spoke VPN.
The Hub i a FGT 60C with OS 5.2 Patch 11
The Spokes are two third-party Routers (AVM Fritzbox 4020, german manufacturer) as dialup-IPSEC-connections
What i have is:
two route-based IPSEC-Tunnels from the Fortigate to those two routers.
I can ping from the Network behind the hub to the Network behind each spoke and from each Network behind the spoke the the Network behind the hub
so far, so good but i am unable to get a ping from spoke to spoke. What I tried:
- create a Zone containing both spoke ipsec Interfaces and disable "block intra-Zone-traffic"
- create a Zone containing both spoke ipsec Interface, leave "block intra-Zone-traffic" and create a policy from Zone to Zone always all accept, NAT enabled
- create each pair of security policies spoke1 to spoke2 spokelan1 to spokelan2 akways all accept, NAT enbaled
whatever I´m trying, i can´t get this working
When i trace data package from spoke1 lan Client to spoke2 it Ends at the spoke1 router, so i assume the packet is being transfered into the tunnel
Any good advice?
Regards
Andreas Maier
