Hello All,
I’m working on a case and would like your input on the best approach to resolve it.
The current setup is as follows:
FortiSASE is configured as a spoke to a FortiGate “Hub” via SPA hub-and-spoke.
Two branch FortiGates are connected to the Hub through IPsec VPN tunnels.
My goal is to allow FortiClient users connected to the FortiSASE to access resources located behind both branch FortiGates.
Do you have any recommendations or best practices on how to implement this?
Hello @BIRO ,
I don't have experience related to topology. But if I think logically, you can use existing ipsec tunnels for service access. Normally direct tunnel from the branch to SASE would work better than this scenario, but if I know correctly, you should buy a SPA license for these branch FortiGates. Because of that, your scenario looks like the best implementation scenario now.
Thanks for your reply.
I am aware of purchase of new SPA license for the branch, but I am looking for a work around to access private network behind the branches firewalls.
User | Count |
---|---|
2570 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.