Hi everybody,
i try to get the following setup to work but i can´t find a solution:
i have a FGT-60C in the headquarter and a FGT-60D in another office. Both are connected with site-2-site VPN interface mode.
I also have 3 FortiAP 14C connected to headquarters 60C with chapwap.
Is it possible to connect the FortiAPs with the existing site-2-site VPN? The remote offices (FortiAPs) should be able to reach the network behind the 60D unit
Regards,
Andreas
As long as routes&policies exist on both sides and connected over the vpn tunnel, it should work. Not working?
I´m afraid it does not. But i guess, missing routes and policies are the reason. But I am not sure which routes and policies have to be set.
I set up the site2site vpn with the wizard, so there are 2 policies, internal to ipsec tunnel interface and ipsec tunnel interface to internal. And a route forcing the remote office´s LAN through the ipsec tunnel interface.
What policies and routes have to be added to connect the remote office to the forti aps and the aps to the remote office?
Internal interface generally doesn't include wifi interface (associated with SSID) unless you changed from the default 60c config. Either you need to attach the wifi interface to the existing policy or create a zone to include both and use it in the policy. Make sure your vpn config (IPSec phase2-interface) includes the wifi subnets in networks on both 60x either source or destination. You can add that part via CLI once you confirmed what you have now.
Then check how far an end device can reach toward the other side with traceroute.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
761 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.