SSL VPN into existing subnet
Is it possible to let fortigate hand out ip-adresses to ssl-vpn users from an existing subnet on the fortigate router where physical devices are also connected?
We have a customer that has an additional secure connection for health-related traffic. The third party router for that connection (i will name it 'secure router' from now on) has a /24 subnet (i will name it 'secure subnet' from now on) which is configured in the fortigate. We have routing policies in place to route the correct traffic to the secure router and the firewall policies is in place with SNAT actived so the secure router sees traffic from an IP of the ./24 subnet. Traffic is flowing without problems over the secure connection so the basics are all in place.
Clients use ssl-vpn to connect from various locaties. They get an ip-address from a pool that is created for these vpn users.
They use a prorgam that connects to a service behind that secure connection that uses the local IP of the client as identification. SNAT does not work as the application is sending it's local IP to the server. However the server can only be configured with ip's of the secure subnet, not the ssl-vpn subnet. So we would need to hand out ipadressen of the secure subnet directly to ssl-vpn user when connection.
I can give out the correct secure subnet IP-adresses to the vpn-client but then no traffic is flowing. I have some ideas why but that might just confuse things to note here.
