Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Atheonux
New Contributor

Parse all Traffic through Azure IPSEC VPN

Hi everyone,

Here's hoping someone can assist with something I've been battling with now for some time. I'm really new to Fortigate with just over 1 year experience on the devices - please don't bite my head off if this sounds like a noob question :)

 

I have successfully established a VPN Tunnel to Azure using this guide:
https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/587640/ipsec-vpn-to-microsoft-azure

Is it possible to route all traffic (specifically browsing services) through the VPN gateway?

I am trying to get all workstations in the Local Fortinet network, South African (SA) based with South African IP address to reflect the Gateway (Azure) IP address.

 

Ideally all I need to achieve is workstation on SA side being able to run a "CheckMyIP" and reflect the Remote Gateway (Azure) IP Address rather than the SA one.

 

Any help would greatly be appreciated :)

Thank you so much

1 REPLY 1
sagha
Staff
Staff

Hi Atheonux, 

 

You can use this guide as a reference: 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Remote-browsing-over-IPSec-VPN-tunnel/ta-p...

 

Important things: 

1. Phase2 selectors should have destination configured as 0.0.0.0 on FGT. 

2. A policy allowing all traffic between LAN and IPsec interface on FGT. 

3. A default route pointing towards Ipsec interface. 

 

This will help in routing all traffic via IPsec tunnel. 

 

If you still have more questions, let us know ;)

 

Thank you. 

Shahan

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors