Skip to main content
robertwb2
New Member
April 28, 2017
Question

Site-to-Site VPN Routing Internet Traffic

  • April 28, 2017
  • 19 replies
  • 41480 views

So I have something I thought would be quite simple, but I just cannot wrap my head around. 

 

Right now, I have a Site to Site IPSEC VPN setup between my two 100D Fortigates. 

 

What I'm looking to do is route all the traffic from Site B thru Site A so we can use some of the public IPs available at Site A over at Site B. My best thought was to route all the traffic from Site B to Site A and exit out to the internet at Site A, but I cannot get the internet traffic to go thru the tunnel and I was hoping someone could step me thru it and see what I'm doing wrong.

 

Thanks so much

Robert

    19 replies

    ede_pfau
    SuperUser
    SuperUser
    April 28, 2017

    So, what have you done so far? Do you have a default route in place? Policies?

    MikePruett
    New Member
    April 28, 2017

    Yeah, give us an example of how things are on the Gates and we can point you in a general direction.

    rwpatterson
    New Member
    April 28, 2017

    For starters, if you want the Internet traffic to flow through the tunnel, you should set that distance shorter than that of your default gateway (at site B). The tunnel should be your preferred gateway, in other words. You may still wish to go out directly for things like DNS, but that's your call.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!