Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sandeshpatil6524
New Contributor

IP Sec VPN multiple subnets

I want to add multiple subnets in my existing IP Sec VPN tunnel.

could you please suggest is it possible??

10 REPLIES 10
ozkanaltas
Valued Contributor III

Hello @sandeshpatil6524 ,

 

Yes, you can. You need to just add button on the phase 2 selectors area in existing ipsec tunnel configuration. 

 

After clicking, a new phase 2 configuration area will show. 

 

image.png

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
sandeshpatil6524

Yes i found this tab and also added this in phase 2, but unable to ping from my remote location to office location.

 

 

 

ozkanaltas

Hello @sandeshpatil6524 ,

 

Did you add a static route and policy for the new subnet? Because ipsec needs these two components to bring up the tunnel. Also, you need to configure it on a remote site for a new subnet. If you didn't do that tunnel won't be up.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
sandeshpatil6524

can we connect over call?? its better to describe what actually i want

sandeshpatil6524

if yes my contact no is +919623746857

ozkanaltas

Hello @sandeshpatil6524 ,

 

We can't make any calls. This platform is a community. If you want to get support with a call, you can create a case to Fortinet support. Fortinet support engineers can make calls with you.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
sandeshpatil6524

Hi Ashideep,

 

Thanks for the information,but im using tplink er 605 vpn router at my branch site.

so how could  it be working?

SonaMuvv

Hello,

Once the phase 2 selectors are added on either end of the vpn tunnel.
1) Make sure there is a static/dynamic route to the remote address(mentioned in the phase 2 selector)

-verify the routing table - get router info routing-table details x.x.x.x  ---> remote ip address

2) Make sure you have policy to allow the traffic for that specific phase 2 selectors

3) You will have to check the above mentioned points on both firewalls

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors