Routing across VPN to VLAN
Hello everyone,
I hope someone can help with this. I am trying to route traffic across our VPN to a VLAN and back again. My setup is as follows:
SiteA -> Fortigate 100D -
-Port13 connected to VLAN10 on Cisco core switch with switchport mode access.-Port13 is getting an IP address (192.168.210.72) from the DHCP server on VLAN10 (192.168.210.0/24)
-I can ping the DNS server and gateway on VLAN10 from the 100D.
-Ipsec tunnel to 60c at SiteB
SiteB -> Fortigate 60C -
-Ipsec tunnel to 100D at SiteA
-I setup a VLAN11 at SiteB to give out IP addresses on 192.168.211.0/24 and set the DNS server address the same as SiteA VLAN10.
-I setup the policies to allow traffic from VLAN11 subnet 192.168.211.0/24 across the IPSec tunnel.
-I can ping the Port13 IP Address (192.168.210.72) on VLAN10 at SiteA over the IPSec tunnel.
-I cannot ping the DNS server or any other IP address on VLAN10 at SiteA from SiteB.
I am really just trying to allow SiteB to talk to the VLAN at SiteA. What would be the best way to do this? Should Port13 be setup with a Vlan subinterface? I have tried using a dynamic nat pool to map the traffic from the SiteB with the same subnet as SiteA. At the same time, I used VIPs for the inbound traffic when I did this but it didn't work. Please help as I am a wit's end.
Thanks...
