Skip to main content

7 replies

przemo
New Member
May 10, 2016

Hello, In the past, I used this recipe on two FGT60D 5.2.5. so I think that it is complete and correct. Perhaps you omitted one step?

ede_pfau
SuperUser
SuperUser
May 10, 2016

You are right, the recipe as given will only work under very special circumstances.

What is missing is the default route (0.0.0.0/0) on the remote FGT pointing to the tunnel interface.

 

The author describes to set up a static route to the HQ public IP address as a host route (172.20.120.154/32) but makes his first mistake to make the network mask too large (as /24). This will not prevent the tunnel from coming up but will make a lot of hosts on the internet inaccessible. As a host route (/32), this route will enable the remote FGT to reach the HQ FGT to establish the tunnel.

 

When the tunnel is up, traffic will only traverse the tunnel via the 'HQ private LAN' route to destinations on the HQ private LAN. To reach the internet across the tunnel, you need a default route on the remote FGT pointing to the tunnel interface - and this is missing.

 

It's distance doesn't really matter actually - if the tunnel is down, the explicit host route suffices to enable contact to the HQ FGT. And once the tunnel is up, a default route with any distance will do.

 

Frankly, I don't understand that Keith Leroux hasn't edited the recipe - users have pointed out the mistakes months ago. I hope he (or someone from Docs dept.) will read this.

fb1907
fb1907Author
New Member
May 10, 2016

Thank you very much Ede.

 

For this link : http://cookbook.fortinet.com/remote-browsing-using-site-to-site-ipsec-vpn/

 

Firstly, ı will do ipsec vpn sitetosite with using wizard. For remote office,Then, i will correct static route( dst:0.0.0.0/0, device:tunnelinterface) and i will add static route (dst:172.20.120.154/32, bu t i did not understand what the device and gateway is?)

 

Are there true?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!