Skip to main content
Cornelis
New Member
May 20, 2019
Question

IPsec site to site routing traffic

  • May 20, 2019
  • 3 replies
  • 3251 views

Hi All

 

I am pretty new to fortinet products and was hoping that someone could guide me in the right direction.

 

I have 2 fortigates where i have created a site to site vpn. The tunnel is up between hq and remote office. I need to route all traffic from a vlan from remote office to hq, so bassicaly the remote vlan has the same public IP as HQ.

 

Many thanks in advance

 

 

    3 replies

    ede_pfau
    SuperUser
    SuperUser
    May 20, 2019

    What? remote and HQ have the same public IP? Could you please clarify?

    Cornelis
    CornelisAuthor
    New Member
    May 20, 2019

    Sorry, they have different IP's, i need the vlan from remote office to route through gateway of HQ so it looks like the remote machine is sitting in HQ 

     

     

    sw2090
    SuperUser
    SuperUser
    May 21, 2019

    Well in this case your remote office GT will have to have a static route toa subnet at HQ used for this. This oute must go over the IPSec Tunnel.

    Then you would need a policy that comes after your outher policy on remote Site FGT (but before Policy 0) which will alllow traffic from client subnet to everywhere via the IPSec Tunnel.

    HQ FGT will then need a static route to remote client subnet over the IPSec Tunnel plus a Policy that allows traffic coming from the Tunnel with remote subnet as source and internet Port(s) or SDWAN as destination with NAT enabled.