IPSec remote => IPSec site to site (Cloud based)
Hey everyone,
First of all, we've search for our problem on the forum but even if there were posts about it, we couldn't find any solution.
We're facing a problem right now regarding the VPN of our company.
Our devices :
- 2 x Fortigate 100F (HA) in HQ with 7.0.1 Firmware.
- 1x FortiGate VM64-AZURE on Azure with 6.4.8 Firmware.
- Forticlient VPN for remote users.
At the moment we have SSL and IPSec remote connections to HQ for remote users and everything works fine.
When we've added a platform on Azure Cloud as you can see on the topology below, we created an IPSec site to site VPN.

It's working fine for the users on the LAN and we've modified the firewall configuration for the SSL VPN so the remote users can access the Azure Cloud.
The problem is that we don't know how to do the same with the IPSec remote users as when we configure the remote IPSec tunnel, we can't chose the VPN (Azure) interface, only local interfaces can be added.
We've kind of replicated the topology in a lab and tried different approaches but still aren't able to make the IPSec remote => IPsec site to site connection to be successful.
I'd like to know if you could help us understand how to do the configuration, if it's even possible :).
Thank you very much,
GiGi.