Hello,
I have three FortiGate firewalls: A, B, and C.
- A ↔ B: IPsec tunnel
- A ↔ C: IPsec dialup tunnel
I want to allow communication between B and C **without a direct tunnel**, by using FortiGate A as a **VPN hub**.
Is this setup supported, and what are the best practices for routing, phase2 selectors, and policies in this case?
Thank you!
FortiGate supports hub-and-spoke VPN topologies where one firewall acts as a central VPN hub. Proper configuration of phase 2 selectors, routing, and policies will enable B and C to communicate via A without establishing a direct tunnel. Always test connectivity and monitor logs to ensure smooth operation.
User | Count |
---|---|
2593 | |
1381 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.