Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NKL
New Contributor III

IPSec VPN with overlapping subnets

Hi all, I'm trying to connect two sites through IPSec VPN, that are using the same ip subnet (let's say 192.168.100.0/24) for their local LAN. Both sites a running a FortiOS 5.2.7. The goal is that devices on Site1 can communicate with devices on Site2, although their ip subnets overlap. I'm aware that there are both a Fortinet-doc (http://docs.fortinet.com/...erlapping-subnets.pdf) and a cookbook recipe (http://cookbook.fortinet....-overlapping-subnets/) for that. Unfortunately, both don't seem to work or match my requirement. As for the doc, at the beginning, it sounds like the solution to my problem. But only very late, in "Results", it is explained that Site1 and 2 will actively have to communicate with a mapped ip range. And the cookbook recipe does not even seem to be complete at all, that is VIPs being created but never used in the recipe. Has anyone a working solution to my requirement and is willing to share his/her config with me?
11 REPLIES 11
rwpatterson
Valued Contributor III

Change the subnet on one (or both) sides. More work now leads to less pain later.

 

My two cents.

 

<aside>Many times I have stressed the point that you should always avoid using default network subnets in your setups. The common subnet ranges (192.168.0.x/24, 192.168.1.x/24, 192.168.2.x/24 for example) are going to be used by less knowledged (or just plain lazy) folks and down the road you'll eventually run into some other party using this common scheme and have this same situation in triplicate. Changing the least impacted side at this time will save many headaches down the road when you do need to connect with a third entity using 192.168.1.x/24.</aside>

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
sw2090
Honored Contributor

Well we use that internal only so no problem so far.

We just bought a shop that already has this net and we first of all wanted some vpn to there before we rebuild their lan ;)

In fact I couldn't get it to work using Keith's Howto in the Cookbook. Either he is missing something in there or it does not work that way any more in 5.4 or newer at all.

 

However I finally found the KB Article: http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD33872&sliceId=1...   and this works fine even with FortiOS 5.4.x .

 

cheers 

Sebastian

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors