Skip to main content
xavi87
New Member
August 8, 2016
Question

IPSEC Dial up VPN - can't access remote sites.

  • August 8, 2016
  • 2 replies
  • 4934 views

Hi! I'm currently having a problem with ipsec vpn. Hope you can help me :)

I have 3 FORTIGATES 90D with 5.4 FortiOS, connected via IPSEC Tunnels and in each site i can access the remote networks but now i'm trying to access the remote networks when i'm out of the company, with forticlient and a dial up ipsec tunnel.

So, i have this: SITE A: 192.168.1.0/24 SITE B: 192.168.2.0/24 SITE C: 192.168.3.0/24 They are connected with each other . SITE A<----->SITE B SITE A<----->SITE C SITE B<----->SITE C

What happens is, when i connect via forticlient (i connect to site A), i can access the A SITE resources but i can't reach the other sites.

For example, this is the policies for the site-to-site tunnel between A and C NAME----------------FROM-------------------TO----------------------------SOURCE------------------DESTINATION-------NAT ZI_PP_Local-------internal----------------ZI-PP(ipsec tunnel)------------192.168.1.0/24----------192.168.3.0/24--------NO ZI_PP_remote----ZI-PP(ipsec tunnel)-------intenal-----------------------192.168.3.0/24----------192.168.1.0/24--------NO

And this is the policy for the IPSEC dial up:

NAME----------------FROM-------------------TO----------------------------SOURCE------------------DESTINATION DialUp---------------dial_up_tunnel------internal/ZI-PP/ZI-PS ---------vpn_range----------------the 3 networks 1/2 and 3.0

,NAT DISABLED and all services permited.

legend: ZI_PP: tunnel beteween site A and C ZI_PS: tunnel between site A and B vpn_range: 25.25.25.1-25.25.25.100 it's the range i defined to the users that connect via forticlient.

The site-to-site tunnels are working very well but when i connect via dial up, i can only access the 1.0 network.

Thanks in advance for any help.

 

 

 

 

 

 

 

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    August 8, 2016

    Do Site B and C know 25.25.25.x is located at Site A?

    ede_pfau
    SuperUser
    SuperUser
    August 8, 2016

    Enable NAT in the policy 'SSLVPN' to 'internal' so that your VPN client appear to have an IP address from the local LAN "A". You should then be able to reach site "B" and site "C".

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!