Skip to main content
Dom5
New Member
March 26, 2020
Question

Remote SSL VPN network is the same with the central Server network

  • March 26, 2020
  • 1 reply
  • 2366 views

Hi All,

 

I have the following dilemma where the remote site is the same IP range as the head office site.

I am configuring SSL VPN to access from the remote site. 

 

Is there away to configure without change the central office IP range?

 

I tried to follow the old kb but it did not work. 

 

I am using Fortios 6.2.3

 

Dom

 

1 reply

Toshi_Esumi
SuperUser
SuperUser
March 26, 2020

I'm assuming you're using tunnel mode with FortiClient. Then the problem happens on the client side since it sees the destination is on the local network. I haven't done this but I would think it would work if you assign a different subnet for the servers then set 1-to-1 VIP (you might need SNAT w/ ippool as well if the sever side needs to initiate sessions toward the client) with the real IPs, then apply them to the policy from ssl.root to the server interface.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.