Created on
09-05-2024
11:56 PM
Edited on
09-05-2024
11:56 PM
By
Anthony_E
Description | This article describes how to steer internet traffic to overlay links from the Branch to the HQ |
Scope | FortiGate. |
This will provide centralized inspection, network management and control on the HQ:
To steer the Internet traffic from the branch office tunnel to the HQ, configure the below settings on the tunnel:
On HQ Fortigate. Make sure HQ FortiGate can reach internet traffic from wan1:
exec ping-options interface wan1 exec ping google.com
Apply necessary security profiles and inspection from this firewall policy.
On Branch Fortigates.
config firewall policy
config router static edit 1 set dst 15.1.1.1/32 <----- HQ Wan IP. set gateway 25.1.1.254 <----- Branch Gateway. set device wan1 set distance 1 next edit 2 set dst 0.0.0.0/0 set device VPN_Tunnel set distance 5 end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.