Hello,
I have ipsec vpn connection from my main office with branch office, now I need to create ipsec vpn for a customer that should have access to branch office lan, but connection will be created at main office Fortigate, not directly at branch office.
Main office:
LAN: 10.1.0.0/16
IPSEC to branch use 0.0.0.0 / 0.0.0.0 as phase 2 selectors
I have connectivity from main office to branch lan.
Branch:
Lan: 10.5.0.0/24
Ipsec to main office.
Customer:
need to connect using ipsec vpn to my main office, but should get access to 10.5.0.0/24 network
How could I do this?
For the customer VPN part, not much different from branch. Just need to set a network selector like customer_network/xx<->10.5.0.0/24 if no conflict/overlaps for those networks.
Then you need to adjust/add an additional network selector to Main-Branch VPN to allow customer_network/xx can come though. And then you need to have proper routes and policies to allow it on both Main and Branch offices.
User | Count |
---|---|
2063 | |
1176 | |
770 | |
448 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.