Skip to main content
dholton912
New Member
December 27, 2023
Solved

IPSEC Site-to-Site force vlan for Internet

  • December 27, 2023
  • 2 replies
  • 3491 views

I have a site-to-site link between two offices and I need to force one VLAN from site A to use site B as it's gateway for internet access. Currently the site-to-site link allows for devices from either network (including other VLANs) to communicate with each other, but they use their home firewall for internet access. I need this one site A VLAN to go out site B's firewall for internet access. 

Best answer by abarushka

Hello,

 

I think that policy route may work in your scenario:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-policy-routes-for-route-based-interface/ta-p/193376

 

2 replies

abarushka
Staff
Staff
December 27, 2023
dholton912
New Member
December 27, 2023

It looks like they are using a newer firmware than my FW has. I see they are adding a second Phase 2 selector. How can I do that in v. 5.2?

abarushka
Staff
Staff
December 27, 2023

Hello,

 

In case it is not available in GUI you can try to add it in CLI:

 

config vpn ipsec phase2-interface
edit <name>

dholton912
New Member
January 3, 2024

Also the setting of IPs in the tunnel interface is confusing to me. It shows them being set as 2.2.2.2 and 2.2.2.3. Are these just fillers, where should this IP come from?