Skip to main content
bcp
New Member
May 19, 2020
Question

Site to Site VPN - Up but can only access remote Fortigate

  • May 19, 2020
  • 1 reply
  • 1912 views

I'm setting up two new Fortigate 60F devices, one at a head office and the other at the branch office. Using the VPN IPsec wizard I created IPsec tunnels on each and it shows status: up.

 

However, from a computer at the branch office I cannot access IPs on the head office network (for example, 192.168.20.20) but I can reach the head office Fortigate (192.168.20.1). 

 

Is there another step I need to do?

 

Thanks. 

    1 reply

    sw2090
    SuperUser
    SuperUser
    May 20, 2020

    might mean that you are missing some policy on at least one side?

    You have to have  a policy to allow branch to head office on both sides!

    You already seem to have the required route(s) as you can reach the FGT at head office from branch side.

     

    Also some flow debug on both sides might show you what happens (or does not happen)...