Skip to main content
santgrac
New Member
October 15, 2015
Question

Policy problems / understanding using IPSec Lan-to-Lan VPN

  • October 15, 2015
  • 7 replies
  • 10224 views

Hello, I have to build up a VPN Lan-to-Lan using IPSec from a Fortigaterouter 60B to another network.

I made Phase 1 and Phase 2 and I think the settings are correct because the other side can see the tunnel when I bring it up. But I can't send anything over the tunnel. The problem are the correct settings for the Firewall policies i guess. My network is like follow: My PC has IP adress 192.168.140.13 with gateway 192.168.140.252. In Phase 2 the Source adress is 192.168.17.0/25 and the Destination adress ist 192.168.17.128/25. In Phase 1 I specified the public IP adress from the other network (i'll call it network B) Now what I know from Networks in theory I have to make two routes:  - from my Gateway (192.168.140.252) to 192.168.17.128/25  - from public IP network B to 192.168.17.128/25 One network adress translation:  192.168.140.x/24 to 192.168.17.0/25 Am I right? But there are so many options I can choose that I don't know how to set it up, because when I try to make some traceroutes on my computer or on the CLI Console I never can reach adresses from 192.168.17.128/25 which I know they are online. Which Policy needs to be Action IPSec with VPN tunnel? I tried to make a policy like in the documentation from fortigate: 192.168.17.0/25 -> 192.168.17.128/25 Action IPSec

But there is something missing.. Hope someone can help me Thank you very much

Source address

    7 replies

    gschmitt
    New Member
    October 15, 2015

    santgrac wrote:

     

    My PC has IP adress 192.168.140.13 with gateway 192.168.140.252. In Phase 2 the Source adress is 192.168.17.0/25 and the Destination adress ist 192.168.17.128/25.

    Well there is your first problem.

    Your Source Address for P2 is your internal network, your destination address is their internal network

    santgrac
    santgracAuthor
    New Member
    October 15, 2015

    Hello gschmitt, thank you for your anwser. But it is correct to set in the Quick Mode Selector under Phase 2 the two internal networks or? I am reffering to:

    http://docs.fortinet.com/uploaded/files/1086/fortigate-ipsec-vpn-50.pdf Gateway to Gateway configuration or http://docs.fortinet.com/...te-and-a-Cisco-ASA.pdf

     

     

    santgrac
    santgracAuthor
    New Member
    October 15, 2015

    Hello, I had now a bit more time. I followed the instructions in:

    http://docs.fortinet.com/uploaded/files/1086/fortigate-ipsec-vpn-50.pdf  Page 63

    Gateway - to - Gateway configuration, because the example is like mine. I did the same, tunnel is up but no luck. The tunnel is up, but I think because my computer is in a different subnetwork i have to add something more, like a additional route? And don't know if it is important, but the subnetwork 192.168.17.0/25 does not exist phyiscally. I attached the steps of the vpn, the policies and the static route.

     

    Thank you!

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!