Created on
02-27-2017
03:46 AM
Edited on
01-02-2025
07:50 AM
By
Jean-Philippe_P
Description
Solution
config vpn ssl settings
set dns-server1 192.168.1.x <- Address of remote DNS Server.
end
Local : 10.1000.100.0/28
Remote : 192.168.1.0/24
Note: Ensure SNAT is not set to 'Use Outgoing Interface Address'.
(FortiGate B internal network 192.168.1.0/24)
Action: Accept
FortiGate B Configuration:
Existing IPsec VPN configuration:
Local : 192.168.1.0/24
Remote : 10.100.100.0/28
• Make sure there is a firewall policy to allow traffic from the IPsec tunnel to the LAN.
Note: Ensure SNAT is not set to 'Use Outgoing Interface Address'.
• Make sure there is a static route to 10.100.100.0/28 via FortigateB-vpn.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.