Hi,
We have successfully set up IPSec FortiClient together with the relevant policies. We have 3 sites in all and all users connect to the main site.
Our next plan is to allow users who connect to the main site to be able to connect to servers/services on the remote sites. How can we achieve this when users are connected via FortiClient?
The only issue I currently have is that the VPN wizard created a tunnel interface for the main site but I don't know if I need to create a tunnel interface in the sub-sites as well. If yes (which I assume so), do I need to point the main site tunnel interface to the remote IP tunnel or firewall policies should be enough? Thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @jabal,
I believe you want to allow remote access VPN clients at the main site to access remote site via site to site VPN tunnel. You need to add a phase2 selectors and create firewall policies to allow the traffic. This link has similar scenario: https://docs.fortinet.com/document/fortigate/7.4.2/administration-guide/45836/ssl-vpn-to-ipsec-vpn
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.