Skip to main content
Hasselmusen
New Member
March 18, 2019
Question

Two site-to-site IPsec and overlapping remote subnets

  • March 18, 2019
  • 1 reply
  • 5020 views

I just migrated to Fortigate, and I have 12 IPsec tunnels to different sites.

Site A and Site B has the same remote subnet, and this is a problem because I can only have the same static route to the subnet once.

 

Is this solvable from within the Fortigate?

    1 reply

    James_G
    New Member
    March 18, 2019
    I assume site a and site b are client subnets, and servers are in central site, say site c, then it can be resolved by implementing NAT to hide the duplicated vlans at site a and b. More info on requirement would help, but yes I expect something is possible.
    Hasselmusen
    New Member
    March 19, 2019

    Thanks for your reply James, but I digged a bit deeper into the forums and found this thread: https://forum.fortinet.com/tm.aspx?m=138688

     

    And that is the issue that I have and the solution to the problem. It really isn't simple to fix so we're going to change the subnet instead.

    Hasselmusen
    New Member
    April 1, 2019

    Or, maybe I'll just set it up as a Policy based VPN.

     

    Does Fortigate support Policy based VPNs to coexist with Route based VPNs?

    I can enable Policy based VPNs under Advanced Features, but I want to make sure it does not screw up the already established Route based ones that I have.