Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rospondek
New Contributor

Connect from A to B's encrypted WAN throught VPN

OK I have a 'tricky' problem.

I've got two sites A and B.

They're connected through VPN.

Site B is connected to other encrypted WAN which allows to work on a DB based software.

 

So it looks like this

 

A <- VPN -> B <- VPN -> WAN

 

So the deal now is.

How to, and please tell me it is possible, connect A through B to gain access to the encrypted WAN. It should be possible, but I have no idea what to do to make WAN consider site A as a trusted connection.

 

Any ideas?

2 REPLIES 2
ede_pfau
SuperUser
SuperUser

That's all a matter of routing.

Imagine you are in A. There is a route pointing to B for the subnet behind B (I'm talking about the "private" networks - the WAN addresses don't matter). For a (reply) packet in B, there is a route back to A.

 

Same situation for traffic from B to C (not "WAN"). And in C you need a route back to B.

 

Now, to go from A to C you need a new route in A pointing to the C subnet, gateway is the address of the internal interface in B. For return traffic, you need a new route in C pointing to the A subnet, with the same gateway.

 

So that's only the routing. In order to transport traffic to C you need to allow the C subnet in the tunnel policy on A, and likewise allow A subnet traffic from C through the tunnel to B.

For simplicity, let's assume that the tunnels are always up. If not, you would need to add phase2s to the tunnels AtoB and BtoC.

Wouldn't it be easier to just create a tunnel directly from A to C? Same routing but less phase2s and more simple policies.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
rospondek

A little more technical details cause it is not as easy as it looks.

 

The thing is I've got 5 localisations. 4 of them managed to pass requirements to gain access to the WAN (in other words they got preconfigured routers and additional DSL). One of the sites was too small to gain this requirements.

So now I have to connect (A) to the WAN (C) through other site (B) on these site (B) credentials. I do not have access to the settings of the WAN routers, though I can't do nothing to connect these 5th site to the WAN.

That's why I'm trying to pass connection to this site throught already connected site.

 

I don't know if it is clear enough :(

 

If I had access to the routers of the WAN there would be no problems, I guess.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors