Hi All,
I can't find similar topics through the forum.
Now i have 2 site, let say site A, site B.
there is a vpn tunnel always connect between this 2 site.
Site A subnet: 192.168.1.0/24
Site B subnet: 192.168.0.0/24
Dialup VPN subnet: 10.0.0.1/24
Now i need to setup a dial up vpn to site B, and this client need to able to connect to Site A also.
I am using IPSEC VPN
how can i do it?
Thanks
Setup a Dial up VPN on site B as usual. Assuming you have 0.0.0.0/0.0.0.0 in phase 2 of all VPN's. Add policy and routes on both Firewalls to send traffic to/from VPN subnet.
Thank You
Yes , You can still do that. You have to advertise the VPN users subnet in phase 2 of both Firewalls Site 2 site VPN.
Source will be local subnet of the network behind the firewall and destination will be VPN user's subnet.
Hope this helps.
I'd say in this case you would either have to set them to 0.0.0.0/0.0.0.0 or you would have to add a phase2 selector for the other subnet you need to access.
The rest is bascially routes (at both FGT AND on your vpn client) and policies on both FGT.
So you either will need to enable split tunneling on your vpn or you will have to have all client traffic go tthrouh side B FGT.
We do have this in effect here. There is IPSec dial in VPN for homeoffice users and they can access a service that is outside our site but connected via p2p ipsec vpn without any problem.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.