Skip to main content
sojosselin
New Member
February 25, 2022
Solved

IPSEC client to site With Sdwan

  • February 25, 2022
  • 6 replies
  • 3527 views

Hello,

 

I have Fortinet Firewall 200E with SDWAN configured and I need to configure a VPN ipsec Client to site 

 

I create the tunnel, I added the policy I can connect but I cant reach the local subnet 

 

is there any think specific with sdwan 

 

just for information it works within SDWAN

 

thx for help

 

 

Best answer by akristof

Hello,

 

Thank you for your question.
Just to clarify, you have problem to reach subnet over the Ipsec tunnel from FortiGate or from local lan (or vice-versa)? If you have problem to reach remove subnet from FortiGate and you are using SDWAN with sdwan rules, you might need to use this ping-option:
exec ping-options use-sdwan yes

 

6 replies

Anthony_E
Staff
Staff
February 28, 2022

Hello,

 

May I propose you to have a look in our Knowledge Base:

 

https://community.fortinet.com/t5/FortiGate/tkb-p/TKB20?pageNum=1

 

You will have a lot of articles with a lot of topics.

 

If you do not find the solution there, come back to us and we will find an answer to your question.

 

Regards,

Best Regards
akristof
Staff
akristofAnswer
Staff
February 28, 2022

Hello,

 

Thank you for your question.
Just to clarify, you have problem to reach subnet over the Ipsec tunnel from FortiGate or from local lan (or vice-versa)? If you have problem to reach remove subnet from FortiGate and you are using SDWAN with sdwan rules, you might need to use this ping-option:
exec ping-options use-sdwan yes

 

sojosselin
New Member
February 28, 2022

i have Problem to reach the LAN from VPN 

I can connect on VPN ( client to site ) but i can't reach the site's LAN 

and i thnik its not a problem of ping because  the http don't pass to 

thank you 

akristof
Staff
Staff
February 28, 2022

Hi,

 

Thanks for reply. I am bit confused what exactly is the design. Can you please clarify? Is it like this:
Client < Ipsec VPN > FortiGate <  LAN >

 

or

Client < Ipsec VPN > FortiGate < Site to site tunnel > FortiGate <  LAN >

 

Can you provide some examples of IPs, what is client IP, which IP address you are trying to reach etc. You can use debug flow to at least verify, that the ping/http is being received by FortiGate:

https://docs.fortinet.com/document/fortigate/6.2.7/cookbook/54688/debugging-the-packet-flow

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.