Skip to main content
GraemeM
New Member
December 13, 2024
Question

Remote VPN to 3 site-to-site VPNs

  • December 13, 2024
  • 1 reply
  • 744 views

Hi, we use FortiClient and IPSEC vpn to connect from home to work.  We can access the resources on 192.168.100.0 (main office lan) but we also require access to resources on 192.168.200.0 and 192.168.2.0

 

There is a site-to-site VPN connecting 192.168.100.0 and 192.168.200.0 and 192.168.100.0 and 192.168.2.0

1 reply

xshkurti
Staff
Staff
December 13, 2024

@GraemeM 
You can fix it by adding more subnets under phase2 selectors:
Adding source and destination subnets to IPsec VPN phase 2 configurations | FortiGate-7000 5.4.9 | How to configure IPsec remote access with... - Fortinet CommunityFortinet Document Library


Also remember to allow traffic on firewall policy from ipsec interface to internal port that points to the other subnets

GraemeM
GraemeMAuthor
New Member
December 13, 2024

Hi, sorry i typically use the GUI and not the CLI.  If my site-to-site ip address range is 192.168.2.0/24 and 192.168.200.0/24 and the IP address I pickup after i log into the VPN is 192.168.101.90 is these (see pic) where it goes? 

 

 

 

phase2.jpg