Skip to main content
FortiRally
New Member
May 7, 2018
Question

VPN traffic dying at DMZ on remote side of the VPN

  • May 7, 2018
  • 2 replies
  • 2670 views

Hello,

 

So we are building a main and remote location. Main location wired public internet and remote site is using dual LTE.

 

There is one Machine connected at the Main location, a laptop.

 

At the remote site there is a cisco switch running three VLANs. The tunnel is meant to allow connection between the main site and remote site's VLAN1.

 

We have tried multiple times using the wizard and custom tunnels but we consistently see the same behavior. Traffic from the remote site completes to the main site connected laptop. Traffic from the main site laptop to the remote site is routed to the remote site forti and then fails into the DMZ. It does not route to the VLAN. We have tested this as well with a direct connected laptop to the fortigate internal switch and the same behavior is happening.

 

Notes:

Policies on both ends to allow traffic in and out from the local and remote subnets

VPNSSL address is created and not in conflict with either local or remote subnets

DMZ port is fully disabled on both sides.

Static route is in place on each side as well.

 

 

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    May 7, 2018

    What do you mean by "DMZ port is fully disabled on both sides" while the port is connected to a Cisco switch on remote side?

    rwpatterson
    New Member
    May 7, 2018

    This is a bit intricate. How about some IP subnet information and/or a diagram. Cocktail napkin scanned in is fine.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!