Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
xavi87
New Contributor

IPSEC Dial up VPN - can't access remote sites.

Hi! I'm currently having a problem with ipsec vpn. Hope you can help me :)

I have 3 FORTIGATES 90D with 5.4 FortiOS, connected via IPSEC Tunnels and in each site i can access the remote networks but now i'm trying to access the remote networks when i'm out of the company, with forticlient and a dial up ipsec tunnel.

So, i have this: SITE A: 192.168.1.0/24 SITE B: 192.168.2.0/24 SITE C: 192.168.3.0/24 They are connected with each other . SITE A<----->SITE B SITE A<----->SITE C SITE B<----->SITE C

What happens is, when i connect via forticlient (i connect to site A), i can access the A SITE resources but i can't reach the other sites.

For example, this is the policies for the site-to-site tunnel between A and C NAME----------------FROM-------------------TO----------------------------SOURCE------------------DESTINATION-------NAT ZI_PP_Local-------internal----------------ZI-PP(ipsec tunnel)------------192.168.1.0/24----------192.168.3.0/24--------NO ZI_PP_remote----ZI-PP(ipsec tunnel)-------intenal-----------------------192.168.3.0/24----------192.168.1.0/24--------NO

And this is the policy for the IPSEC dial up:

NAME----------------FROM-------------------TO----------------------------SOURCE------------------DESTINATION DialUp---------------dial_up_tunnel------internal/ZI-PP/ZI-PS ---------vpn_range----------------the 3 networks 1/2 and 3.0

,NAT DISABLED and all services permited.

legend: ZI_PP: tunnel beteween site A and C ZI_PS: tunnel between site A and B vpn_range: 25.25.25.1-25.25.25.100 it's the range i defined to the users that connect via forticlient.

The site-to-site tunnels are working very well but when i connect via dial up, i can only access the 1.0 network.

Thanks in advance for any help.

 

 

 

 

 

 

 

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

Do Site B and C know 25.25.25.x is located at Site A?

ede_pfau

Enable NAT in the policy 'SSLVPN' to 'internal' so that your VPN client appear to have an IP address from the local LAN "A". You should then be able to reach site "B" and site "C".


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors