Skip to main content
JorgeBon
New Member
October 14, 2024
Question

Vpn Ipsec

  • October 14, 2024
  • 3 replies
  • 1220 views

Hello good morning a question, if I have a site to site VPN and my main segment is the 10.20.0.0/16 and my branches that connect is the 10.30.0.0/24, how can I do it so that all the branches can see one in particular the 10.30.14.1

I thank you for the help

BEST REGARDS

 

3 replies

hrahuman_FTNT
Staff & Editor
Staff & Editor
October 14, 2024
johnathan
Staff
Staff
October 14, 2024

It is not clear what the issue is based on the information provided.
Are you trying to say you have '10.30.0.0/24' located on each of your branches, and they overlap with other branches?
You want to allow your other branches to access '10.30.14.1' on one specific branch?
This should be possible if you use a VIP to map the '10.30.14.1' to a different IP, then use that as the IP to contact the server.

See more details here: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-an-IPsec-tunnel-with-Overlapping/ta-p/242267

Never trust a computer you can't throw out a window.
Toshi_Esumi
SuperUser
SuperUser
October 14, 2024

Or, just want to know how to route a branch to another branch in hub-and-spoke topology?
If so you need to solve:
1. routing
2. phase2 network selectors
3. policies
at all FGTs on the path.

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!