Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Doodley
New Contributor

Redirect specific traffic to VPN connection

We have some problems when connecting to a certain website, tabs are loading intermittently but is loading fine to one of our office overseas. We have Fortigate firewalls on both location and a VPN configured to link both offices. Now, from Office A (where I am now) we can' t access the website (WW.XX.YY.ZZ-WW.XX.YY.ZZ subnet range) completely and I want to redirect every connections made to that subnet range to our overseas office thru the existing VPN. Firewall objects and Policy were already in place but when I tried to tracert the site, I am still connected locally and traffic are not even passing thru the VPN link. What am I missing here?
24 REPLIES 24
Christopher_McMullan

Except the remote source wouldn' t also be 192.168.50.0/24.

Regards, Chris McMullan Fortinet Ottawa

Doodley

I managed to remove an active policy w/c interferes with my pathping/tracert. I can execute the commands successfully but observed I' m still ' routed' with my local ISP' s IP address. I can not see or I' m not being tunnelled to the remote location as seen in my tracert/pathping results. What could be missing in the configuration? Thanks again.
Doodley

Created the Phase 2 connection and Policy for both sites but couldn' t produce a correct tracert on my working PC, tried tracerting the websites IP address but it still returns my own Local public IP address. I figured out that under VPN->Monitor->IPSec Monitor, my second phase 2 connection is DOWN and I coudn' t put it UP on both sites. What am I still missing here?
Doodley
New Contributor

I created a second Phase 2 connection for both sites, followed every instructions stated above for both source and destination addresses. LOCAL LOCATION Phase 1: VPN HK -> There' s a phase 2 connection in here so I created a second phase 2 connection and named it as VPN-HK-P2-1 (VPN-HK-P2 already exist) Source: 192.168.50.0/24 Destination: IP range of website REMOTE LOCATION Phase 1: VPN SG - > There' s a phase 2 connection in here so I created a second phase 2 connection and named it as VPN-SG-P2-1 (VPN-SG-P2 already exist) Source: IP range of website Destination: 192.168.60.0/24 Settings for the second phase 2 connections were the same as the 1st phase 2 connections. (Encryption, auto keep alive, PFS, ...) Connection created, but when I tried to pathping/tracert the website - it gives me: Request timed out. What am I missing here? Thank you.
Christopher_McMullan

Request timed out would mean all the necessary intermediaries responded to ARP requests and either sent on the packet or dropped it. Can you run sniffs and flow traces? Run this in two separate windows, one from the local FGT and one from the remote: di sniff pack any " host w.x.y.z" 4 //--website address See if it flows through both devices. Then a flow trace: di de reset di de en di de fl s c en di de fl s f en di de fl filter addr w.x.y.z //--website IP di de fl tr start 5000 Try the ping/traceroute, then... di de fl tr stop di de fl filter clear di de reset di de di Perform the flow trace on both units. It will show you if a tunnel is not ready to take the traffic, or if a policy drops the packet...basically any blockage up to Layer-4, plus VPN.

Regards, Chris McMullan Fortinet Ottawa

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors