Skip to main content
fortinetuser2020
New Member
April 11, 2017
Solved

need a routing solution between 2 fortigates

  • April 11, 2017
  • 14 replies
  • 27133 views

hi all

see attached diagram, it'll help explain it better

 

i don't know how to "attack" this

thank you

    Best answer by ede_pfau

    Definitively a routing issue, but not on the office FGT but on your office hosts.

    Their default gateway has to be 192.168.13.1, the office FGT. These hosts do not need to know anything about the 1.1.1.0 LAN - the default route takes care of all non-local subnets for them.

     

    If the situation at the farm is similar then I suspect that the host settings there are incorrect as well. Farm default gateway is 192.168.16.1.

    14 replies

    ede_pfau
    SuperUser
    SuperUser
    April 11, 2017

    Nice diagram!

    Imagine you are a packet on the farm's PBX on your way to the main PBX gateway. You need to know the addresses of all routers between you and the target address. On each router on the way, you store the info of target network and (only) it's next hop (= next router address) as a static route.

     

    Starting at farm VM (192.168.16.x): target is office PBX gateway at 1.1.1.254

    1st router is farm FGT (192.168.16.1)

    needs to know where 1.1.1.0/24 is: via 192.168.13.1

    so, needs to know where 192.168.13.0/24 is: behind VPN tunnel (no gateway needed here as VPN Ipsec tunnels in FortiOS usually do not have IP addresses at their endpoints ('unnumbered'))

     

    Next router is Office FGT (192.168.13.1):

    needs to know where 1.1.1.0/24 is: via 192.168.13.5

     

    Next router is Office LAN NIC (192.168.13.5):

    needs to know where 1.1.1.0/24 is: directly connected via 1.1.1.1

     

    So, counting all 'needs to know' you need 4 static routes on the routers involved.

     

    BTW, your tunnel needs to carry both the 192.168.13.0 as well as the 1.1.1.0 network (phase2, Quick mode selectors). Just create one phase2 for each network and bind it to the same phase1.

     

    fortinetuser2020
    New Member
    April 11, 2017

    Hi

    first of all, thank you! :)

    second, lets ignore 192.168.13.5, that's actually a vm

    i'm making another diagram of what i've got so far, maybe you'll have an idea

     

    ede_pfau
    SuperUser
    SuperUser
    April 11, 2017

    Sure, at least 2 routes are missing.

    We can proceed if you post the existing routes on .16.1 and .13.1. And can't without.

    fortinetuser2020
    New Member
    April 11, 2017

    thank you

    these are the static routes from both sides

    the upper one is the farm and the lower one is the office

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.