I'm having an hard time to forward internet traffic over IPsec tunnel for specific subnets, basically i want that computers in the siteB subtnet access the internet though SiteB gateway via the IPsec tunnel.
This is the official documentation:
First of all it's poorly explained how to add the gateway to the phase 2 selectors (Note: make sure to include the gateway IP in phase 2 selectors of the tunnel to allow traffic)
Can someone more advanced that me explain how to do it? Many thanks
Hi mass1q,
You can refer to the below document where @saneeshpv_FTNT described exactly what to do.
Regards,
Created on 02-27-2025 01:03 AM Edited on 02-27-2025 03:23 AM
Thank you very much, it helped me a lot. I needed to forward all internet traffic from site B (branch) to site A (HQ), route policy was the key to make it happen. I also had to assign static ip to the IPsec interfaces and set the remote one as gateway in the route policy.
In case tunnel goes down I also need to block all traffic going to the site B local WAN, is it possible? Basically I want that internet for site B is reachable only through the IPsec in site A
User | Count |
---|---|
2626 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.