Multiple local subnet interfaces for IPsec VPN
We have two FortiGates (100E & 200E) that we want to establish a VPN between. Both firewalls have a local VLANs configured (via FortiLink managed FortiSwitches). We want all VLANs communicate over the VPN.
When using the FG-FG VPN wizard, I have noticed I am required to choose a local subnet interface. In our case we want all our VLANs but this is not possible in the wizard.
What would you recommend? Perhaps I could create a zone but this would require I recreate all our firewall policies. Is this the preferred way?
Or maybe I should create the VPN using the custom wizard. I can't see a requirement for a local interface.
Cheers.
Dunc
