Hello,
I've just created a FortiClient VPN (Client‑to-Gateway IPsec VPN) on a FortiGate unit that already had a site-to-site VPN set up.
When I connect to the FortiClient VPN that I created, I can reach LAN resources behind the internal interface but I cannot reach resources behind the site-to-site VPN interface. I created 2 Firewall rules, one allowing trafic from the FortiClient VPN interface to the site-to-site VPN interface and another one from the site-to-site VPN interface to the the site-to-site VPN interface but it still doesn't work.
What am I missing?
Please check the network diagram with the VPNs and flow of traffic that is working vs not working.
Solved! Go to Solution.
Make sure the remote FGT knows your source LAN address space. It needs a static route for this.
Suppose your FC has IP 10.2.3.4. Your local FGT will know about that range, otherwise you couldn't surf the LAN. The remote FGT, receiving traffic from 10.2.3.4, drops it as "unknown". So create a static route, destination "10.2.3.0/24", gateway address (none), interface site-to-site-tunnel.
Second prerequisite is that the tunnel will carry that traffic as well. Have a look at the s2s-phase2 Quickmode selectors. Between FGTs, you may use the wildcard '0.0.0.0/0', thus permitting any traffic to open tunnel negotiations.
If 10.2.3.0/24 is missing in phase2, either add another phase2, or switch to wildcard addressing. This needs to be done on both sides of the s2s-tunnel.
Make sure the remote FGT knows your source LAN address space. It needs a static route for this.
Suppose your FC has IP 10.2.3.4. Your local FGT will know about that range, otherwise you couldn't surf the LAN. The remote FGT, receiving traffic from 10.2.3.4, drops it as "unknown". So create a static route, destination "10.2.3.0/24", gateway address (none), interface site-to-site-tunnel.
Second prerequisite is that the tunnel will carry that traffic as well. Have a look at the s2s-phase2 Quickmode selectors. Between FGTs, you may use the wildcard '0.0.0.0/0', thus permitting any traffic to open tunnel negotiations.
If 10.2.3.0/24 is missing in phase2, either add another phase2, or switch to wildcard addressing. This needs to be done on both sides of the s2s-tunnel.
Thank you for the quick reply.
I will try that and let you know if it worked. However the remote VPN Router isn't a FortiGate but I suppose that the same applies.
Hello,
I don't have access to the remote VPN Router of the site-to-site VPN but the person that manages it says that it is correctly configured to allow access from a remote Dial-UP VPN from our side.
However it still doesn't work. Still unable to ping the remote machine behind the site-to-site VPN.
They suggest that I should activate NAT on either the FortiClient VPN Gateway tunnel or on the site-to-site VPN tunnel but even tough I tried that it still won't work, unless I'm missing something on the configuration.
Can we tell from the attached log what's missing?
Thank you very much for your help.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.