Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nihas
New Contributor

How to add a secondary VLAN to the existing IPSec Tunnel

Hello ,

I have a question.

 

I have a running IPSec Between 2 offices ( FG's)

 

Site Mexico - 10.1.10.0/24 

Site Ontario - 192.168.100.0/24

 

Now I need to add a new VLAN in Ontario L3 Switch - 10.1.100.0/24 , And I need to use this VLAN also for the IPSec .

 

How do I achieve?

 

thanks in advance.

Nihas

Nihas [\b]
Nihas [\b]
3 Solutions
Carl_Wallmark
Valued Contributor

Hi,

 

Create a new Phase2 with your new networks and connect it to the already existing Phase1.

 

You can have multiple Phase2 per Phase1.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

View solution in original post

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
ede_pfau
SuperUser
SuperUser

...and, may I add, create at least one policy from the new VLAN to the tunnel (with the phase1 name).

edit:

Arggh, and on the remote end, add a new static route of course, pointing to the tunnel.

Ede Kernel panic: Aiee, killing interrupt handler!

View solution in original post

Ede Kernel panic: Aiee, killing interrupt handler!
Carl_Wallmark
Valued Contributor

If you add a new network on your side you can always use NAT on your policy.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

View solution in original post

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
4 REPLIES 4
Carl_Wallmark
Valued Contributor

Hi,

 

Create a new Phase2 with your new networks and connect it to the already existing Phase1.

 

You can have multiple Phase2 per Phase1.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
ede_pfau
SuperUser
SuperUser

...and, may I add, create at least one policy from the new VLAN to the tunnel (with the phase1 name).

edit:

Arggh, and on the remote end, add a new static route of course, pointing to the tunnel.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Nihas
New Contributor

"You can have multiple Phase2 per Phase1."

Thanks for the new info.

 

Another question, If I don't have access to the remote FG, and they are not ready to change anything for a particular time.

And from our side we really need to access their resource, so is there any other option?

 

thanks 

Nihas.N

Nihas [\b]
Nihas [\b]
Carl_Wallmark
Valued Contributor

If you add a new network on your side you can always use NAT on your policy.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors