Hi folks,
I'm trying to add another ip subnet range in existing ipsec tunnel which is custom type with phase 1 and phase 2. I have added in existing IPv4 policy traffic in and out policy (source to destination using tunnel interface) that subnet too. but it doesn't seem to be working still can't reach to that ip range from remote ipsec vpn tunnel site.
Question:
Do I need to add that subnet range in phase2 at both end fortinet FW to make it work ?
Does it also require to disable and enable ipsec tunnel?
Thanks
A
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You need 3 things to allow traffic to or from a (new) subnet:
- a phase2 for this subnet
- an address object for this subnet
- a policy allowing traffic to/from the tunnel to (usually) the LAN
- a route pointing to the tunnel if the subnet is on the remote side
I guess the route is missing. Check in Monitor>Routing Monitor.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.