Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ysf
New Contributor

FortiGate VPN Hub

Hello,

I have three FortiGate firewalls: A, B, and C.

- A ↔ B: IPsec tunnel
- A ↔ C: IPsec dialup tunnel

I want to allow communication between B and C **without a direct tunnel**, by using FortiGate A as a **VPN hub**.

Is this setup supported, and what are the best practices for routing, phase2 selectors, and policies in this case?

Thank you!

1 REPLY 1
VinayHM
Staff
Staff

FortiGate supports hub-and-spoke VPN topologies where one firewall acts as a central VPN hub. Proper configuration of phase 2 selectors, routing, and policies will enable B and C to communicate via A without establishing a direct tunnel. Always test connectivity and monitor logs to ensure smooth operation.

Vinay HM
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors