Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
WesleyGrillo
New Contributor II

How to create an access route to a specific website for users connected via IPsec VPN.

Hello, I have a specific website and I would like to access it through remote machines connected through IPSec VPN. The website only allows a connection from my WAN without fortigate. Can you help me access it, please?

9 REPLIES 9
dingjerry_FTNT

Hi @WesleyGrillo ,

 

Some questions:

 

1) What is the web site?  

2) "The website only allows a connection from my WAN without fortigate." 

 

What does this mean?

Regards,

Jerry
WesleyGrillo
New Contributor II

Sorry, I wrote it wrong.

 

I meant that the website only accepts connections from my WAN.

 

Let's assume that the website to be released is www.yahoo.com.br

dingjerry_FTNT

Hi @WesleyGrillo ,

 

Can you elaborate on the use case?

 

For example, you have PC A on the local network, PC B on the remote network over the  IPSec VPN tunnel.  You need to connect to PC B from PC A and access the website from the local Internet access on the PC B.

 

Something like that.  It will help us to better understand what you need.

Regards,

Jerry
WesleyGrillo

Hi,
===================================================================
I have a "PC A" on a remote network.

 

I have a "Firewall" on the local network.

 

I have a website called "www.teste.com" hosted on a server in another country.

 

A site-to-client IPsec VPN is configured and is working normally.

===================================================================

"PC A" connects via VPN to the "Firewall".

 

I want "PC A" to access the website "www.teste.com" through the IPsec VPN.

 

The website "www.teste.com" only accepts connection from the WAN1 IP of the firewall.

 

Thanks for the help.

EasyDoesIT

You could set up an FQDN address object for your destination website and use it as the destination in a firewall policy.

Then, configure a static route for the website’s destination and route it over the IPSec tunnel.

If a specific source IP is required, you could add NAT to the firewall policy and assign it the desired IP address for access to your website.

WesleyGrillo

I did it as follows:

However, it didn't work. Can you help me?

 

VPN3.png

dingjerry_FTNT

What is your FortiGate firmware version?

Regards,

Jerry
WesleyGrillo

v6.2.10 build 1263 (GA)

WesleyGrillo

v6.2.10 build 1263 (GA)

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors