- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IP Sec VPN multiple subnets
I want to add multiple subnets in my existing IP Sec VPN tunnel.
could you please suggest is it possible??
- Labels:
-
FortiClient
-
FortiGate
-
IPsec
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @sandeshpatil6524 ,
Yes, you can. You need to just add button on the phase 2 selectors area in existing ipsec tunnel configuration.
After clicking, a new phase 2 configuration area will show.
NSE 4-5-6-7 OT Sec - ENT FW
Created on ‎09-02-2024 03:42 AM Edited on ‎09-02-2024 03:44 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes i found this tab and also added this in phase 2, but unable to ping from my remote location to office location.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @sandeshpatil6524 ,
Did you add a static route and policy for the new subnet? Because ipsec needs these two components to bring up the tunnel. Also, you need to configure it on a remote site for a new subnet. If you didn't do that tunnel won't be up.
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
can we connect over call?? its better to describe what actually i want
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
if yes my contact no is +919623746857
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @sandeshpatil6524 ,
We can't make any calls. This platform is a community. If you want to get support with a call, you can create a case to Fortinet support. Fortinet support engineers can make calls with you.
NSE 4-5-6-7 OT Sec - ENT FW
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ashideep,
Thanks for the information,but im using tplink er 605 vpn router at my branch site.
so how could it be working?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Once the phase 2 selectors are added on either end of the vpn tunnel.
1) Make sure there is a static/dynamic route to the remote address(mentioned in the phase 2 selector)
-verify the routing table - get router info routing-table details x.x.x.x ---> remote ip address
2) Make sure you have policy to allow the traffic for that specific phase 2 selectors
3) You will have to check the above mentioned points on both firewalls
