Question
Site-to-site IPSec VPN from Fortigate to Watchguard
Hi folks - I' m having some challenges when configuring site-to-site IPSec VPNs between a Fortiguard 60c and a Watchguard Firebox XTM 510. The Fortiguard resides at a small branch office and represents one class C private address space - 10.64.130.0/24. The Watchguard appliance is the FW for our main office and where all IPSec VPNs from branch locations terminate. In the past, we were a Watchguard-only shop, and building VPNs between Watchguards is drag-and-drop. Obviously, the third-party thing throws a bit of a wrench in the works. The main office contains the 10.64.0.0/20 subnet. I was able to successfully build a VPN tunnel for this subnet to the branch office - no problem. However, the main office is also the routing location where traffic is transported to our other locations. In other words, we want to provide connectivity to this branch office to our other branch locations that reside on the other side of our main FW. For example, we want to have traffic destined for the 10.65.0.0/20 network from this branch office actually reach its destination. I would summarize the destination on the main tunnel if I could, but the branch office network resides INSIDE of a 10.0.0.0/8, and Fortinet support has let me know this won' t work if there are subnet overlaps. I' m pretty much brand-new to the Fortinet thing, so please be mindful of my noobitude when replying. I would appreciate it. Please let me know if you want/need more info - or even if you' ve just had experience configuring tunnels between Watchguard and Fortinet boxes. Thanks!
