Skip to main content
Hartza
Visitor III
August 30, 2024
Solved

Policy based tunnels in Fortigate

  • August 30, 2024
  • 2 replies
  • 1158 views

Hi,

I'm new with Fortigate and migrating from ASA world.  I'm a little surprised that the fairly basic configuration causes difficulties even for vendor.


The question is: Does version 7.x support setup where traffic should travel from policy-based tunnel to policy-based tunnel and where the NAT should be used for source address. If so, is there any document to follow so that the implementation would be done correctly?  Already found some articles but still wondering do I need VPN Concentrator config to enable traffic flow between tunnels?

 

 

Best answer by Hartza

Finally this was solved out. The main problem was conceptual. In Forti world you have to use route based type of setup instead of policy based even the another peer of tunnel is using policy based type of configuration. Overall this all was terminologically very confusing. 

2 replies

dbhavsar
Staff
Staff
August 30, 2024

Hello @Hartza ,

 

VPN concentrator give you the option to create a hub and spoke VPN, used mainly in some distributed topologies, where you need to centralize resources and access them by a secure connection. And regarding the NAT as long as you are allowing that particular source addresses on other end of the policy-based tunnel. You don't need it

Hartza
HartzaAuthorAnswer
Visitor III
September 18, 2024

Finally this was solved out. The main problem was conceptual. In Forti world you have to use route based type of setup instead of policy based even the another peer of tunnel is using policy based type of configuration. Overall this all was terminologically very confusing. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!