Routing certain traffic over IPSEC VPN
We have site to site VPN between our remote sites and head - office. Both locations are using Fortigate firewalls. We have IPSEC tunnel up and running between these 2 sites. This IPSEC tunnel let our remote site access our servers on the network 10.0.50.0/24.
Here is what we have under phase 2 on our remote firewall as well as head - office firewall:
Remote firewall phase 2:
Source : 10.25.1.0/24
Destination: 10.0.50.0/24
Head-office firewall phase 2:
Source: 10.0.50.0/24
Destination: 10.25.1.0/24
This is a route based VPN with policies for in/out traffic. On the remote site I have a Static route in place for traffic going to 10.0.50.0 (server network at head - office). Static route looks like this:
10.0.50.0/24 network then use device Interface Phase1 of VPN
We have some external server farms which are connected to head - office over IPSEC tunnel and this remote site also need to access those external farms. So rather than creating Site to Site VPN between remote site and external farms, I want to route remote site's traffic through our existing tunnel between head-office. Right now, traffic destined for network 10.25.1.0/24 from remote site only travels over the VPN.
What changes can I make so I can route our remote site's traffic to external farm through our existing tunnel between head - office? Happy to provide more information as required. Thanks all
Regards,
Karan
