Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ehsan230564
New Contributor

Wan to another router

Dear sir,

 

our LAN = 192.168.1.0 /24

WAN = 37.99.167.26

WAN is connected to another cisco router vlan1 = 37.99.167.25

 

LAN user are getting internet through WAN of fortinet 60D.

Cisco router are configure with GRE tunnel.

from router we can reach other side of tunnel.

Also a PC connected directly to cisco router can reach to other side of TUnnel.

 

But PC behind Fortinet 60D can not reach other side of tunnel.

 

I did static route in fortinet to forward all traffic for destination of other side tunnel as well as static route in cisco for incoming traffic for 192.168.1.0 to forward to fortinet.

 

But nothing solving to get the other side of tunnel from behind the firewall fortinet 60D.

 

Kindly send me solution.

 

3 REPLIES 3
Toshi_Esumi
Esteemed Contributor III

Two questions:

1) are you sure either the FGT or the Cisco is NOT NATing this particular path/traffic?

2) If no NAT, does the other end of GRE route back to the GRE for 192.168.1.0/24?

sw2090
Honored Contributor

you write that you have set up the routing. Do you have policies on your FGT which allow the traffic?  Does the cisco have the required firewall rules to allow the traffic?

Does the cisco have a route back to the subnet behind the FGT?

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
ehsan230564

FGT is nating all trafic for internet. yes the other end of GRE route back to the GRE for 192.168.1.0/24.

 

Kindly send me the firewall rules to allow the traffic?, I tried but may be not correct. yes the cisco have a route back to the subnet behind the FGT

 

 

If we bypass the FGT every think is ok, but if the PC is behind the FGT, than we cannot reach other end.

 

FGT are used for internet nating.

And there is two wan link load balancing, round robbin method.

 

Labels
Top Kudoed Authors