I have a pair of Fortigate 60F's, one is in the USA and one is in the UK. I have a Site to Site VPN currently setup but it is a Split Tunnel so all of the web traffic goes through the respective ISP's.
What I want to do is force all of the UK Web traffic to go through the VPN to the US but allow all other traffic to go through the UK isp so I don't have the added latency.
Is there a way to dictate via policy that the traffic of a specific domain/website go over the VPN or even all http/https traffic go over the vpn while everything else is left alone?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I believe your requirement is to send only HTTP and HTTPS traffic over the IPsec tunnel.
Under phase2 selectors, you can use Remote Port and Protocol options. Maybe this will help with your requirement.
It still wouldn't solve routing issue that there needs to be two default routes, one to the tunnel another to the wan interface. You need either policy routes or SD-WAN setup.
Toshi
I'm being told by TAC that the Phase 2 Selectors have to be changed to show 0.0.0.0 rather than the defined subnet...so that everything goes through the tunnel and not just traffic that matches the remote subnet destinations. Then some policy based entries. Not sure if it'll work but i'm going to give it a try.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1717 | |
1093 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.