Skip to main content
Vineeth_U
New Member
March 1, 2016
Question

VPN Unable to Configure

  • March 1, 2016
  • 1 reply
  • 2196 views

Dear Team,

 

I am in the process of a VPN Implementation for one of the client. We have successfully configured Phase 1 but phase 2 is not coming up. I have configured this as Interface Based VPN. 

Client has given few destination IP Address those are Public IPs. I have few questions here, How do I configure this in the phase 2. How do I create policy for this. Is a Static Route required for this. ?

 

PLease help me to configure.

 

1 reply

emnoc
New Member
March 1, 2016

yes and yes  ;)

 

1: a interface-vpn ( aka route-vpn ) needs a route

 

2: just stick the src-subnet(s) in your  phase2-interface cfg

 

3: if your new at lan2lan vpn, the vpn wizzard should be ideal

 

What's on the other end? ( SRX ASA  FGT  )

 

Do you have any subnet overlap issues ?

 

Do you need to SNAT the internal hosts?

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!