Skip to main content
technologist36
New Member
June 7, 2015
Question

Overlapping networks thorugh IPSec S2S VPN

  • June 7, 2015
  • 7 replies
  • 6764 views

Hello,

 

I configured both FG appliances exactly as referenced in this online help document:

http://help.fortinet.com/fos50hlp/52/index.html#page/FortiOS%25205.2%2520Help/gw-to-gw.105.11.html

 

It works but this is not what i expect.

 

The document assumes users to access resources in both ends using 10.21.101.0/24 and 10.31.101.0/24. This means users must memorize these addresses in order to access resources in the other end. I think this is not practical and i want the network to be transparent to end users.

 

I thought both ends can access resources normally using the 10.11.101.0/24. For example, FG_2 translates server 10.11.101.1 > 10.31.101.1.  FG_1 translates PC1 10.11.101.10 > 10.21.101.10. When PC1 pings the server 10.11.101.1, FG_2 will receive the ping request at 10.31.101.1 and then automatically redirect it to 10.11.101.1. When the server replies, FG_1 will receive the reply at 10.21.101.10 and then automatically redirect it to 10.11.101.10.

 

It should work like this.

 

The question is, how does the foritgate know if the ping is intended to a local server with address 10.11.101.1 and not intended through the tunnel?

 

The answer depends on if there is a mechanism in FG to know that.

 

Appreciate your help.

 

    7 replies

    technologist36
    New Member
    June 8, 2015

    Any thoughts?

    Johan_Witters
    New Member
    June 9, 2015

    technologist36 wrote:

    The question is, how does the foritgate know if the ping is intended to a local server with address 10.11.101.1 and not intended through the tunnel?

    I doubt if the Fortigate is able to see the difference... Your method could work as long as you don't have duplicate ip's. eg. client with .1 should either exist at local site OR remote site, but not the 2.

     

    The Fgt will react to requests on the ip's on which it has vips configured, but will not be able to tell if other clients react to the same data on the local subnet

    technologist36
    New Member
    June 9, 2015

    Thanks for your kind reply.

     

    Okay, let's say that i accept the fact i can access resources located at the remote site using a range of VIPs. Now, i am trying to configure a DNS names for these VIPs, so that users can access resources by names.

     

    Let me illustrate what i did and correct me if i am wrong.

     

    I configured the DHCP located at the remote site to give remote users the VIP of the DNS server located in the local site. This is the IP address of the DNS server after translation. Because remote users now see the DNS server as 10.21.101.1, they contact it for names. NSlookup works fine but pings by name failed. Why? Because the host records in the DNS server point to resources with IP addresses in the range of 10.11.x.x/24 subnet and not in the range of 10.21.x.x/2 subnet.

     

    Note: There is no DNS server at the remote site and they rely on the DNS server at local site.

     

    Do you think i need to configure a DNS server at remote site in order for this to work?

     

     

    Appreciate your help.

     

    Johan_Witters
    New Member
    June 9, 2015

    That's correct, the DNS server will reply with the "wrong" ip.

     

    Best way is to install a DNS server locally, either a fixed server, or configure it on the Fortigate.

    technologist36
    New Member
    June 9, 2015

    I believe FG cannot act as a DNS server but it can point to one. I checked the "DNS" under the "Network" section and requires me to specify the addresses of DNS servers.

     

    Anyways, i will try to install an internal DNS server at the remote site and create a FLZ for the VIPs' subnet.

     

    I will let you know the status.

     

    Thx for your help.

    Johan_Witters
    New Member
    June 9, 2015

    technologist36 wrote:

    I believe FG cannot act as a DNS server but it can point to one. I checked the "DNS" under the "Network" section and requires me to specify the addresses of DNS servers.

    Actually you can, but on recent FOS you need to enable "DNS database" in the features view first. After that it should appear under your "Network" section in the menu.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!