Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dholton912
New Contributor

Allow One IP to Remotely Browse through Site-to-Site

Hey everyone!

 

I have a site-to-site VPN between two locations. Is there a way I can pass only one IP address through for remote browsing. For example, I have a subnet of 10.0.0.0/24 on FW A that can access all internal resources on FW B (example subnet of 10.1.1.0/24). I have one workstation (10.0.0.50) on FW A that would need to access the internet through FW B. The rest of the network would still access the internet through FW A. I tried using this KB https://community.fortinet.com/t5/FortiGate/Technical-Tip-Remote-browsing-over-IPSec-VPN-tunnel/ta-p... but am unable to get what I need to work. Any help with this would be greatly appreciated!

1 Solution
hbac

@dholton912

 

I believe your default route is pointing to wan2 which is why it doesn't match the policy route. You will need another static route and point it to the IPSec tunnel. You can create a static route for 8.8.8.8 for testing and point it to the IPSec tunnel. After that, run the debug flow again. 

 

Regards, 

View solution in original post

52 REPLIES 52
hbac

@dholton912,

 

You can have 2 static routes with the same distance. Just give your local Internet route a higher priority so that all other users will only use the local Internet route. 

 

Regards, 

dholton912

That fixed it! Thank you and @mle2802 so much for your help in this matter!!

AEK
SuperUser
SuperUser

You create it on firewall A with source 10.0.0.50.

Try use policy routes for exceptions only.

If you read the tech tip provided by @mpeddalla you will take real advantage of the policy routes.

AEK
AEK
Labels
Top Kudoed Authors