Hi folks,
We have ipsec tunnel vpn site - site between our HQ to branch office. Now branch office has ipsec tunnel with customer.
Our HQ users need to access that customer network which is connected via remote Site - site2 site ipsec tunnel from branch office
I'm using fortigate 200 D in HQ and 100D in branch office. any pointers please.
Is there any option I can route traffic that comes from HQ to remote site towards customers ipsec tunnel?
Its same like we forward sslvpn traffic to ipsectunnel. can we forward ipsec to remote device ipsec tunnel ?
Thanks
Atul
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Yes, ensue you have phase2 proposal and router to the final destination. If you deploy a ipsec phase2 with 0.0.0.0/0:0 and control the route and firewall the HQ should be able to access the final remote site network(s).
Ken Felix
PCNSE
NSE
StrongSwan
Yes, ensue you have phase2 proposal and router to the final destination. If you deploy a ipsec phase2 with 0.0.0.0/0:0 and control the route and firewall the HQ should be able to access the final remote site network(s).
Ken Felix
PCNSE
NSE
StrongSwan
ok - So IPsec tunnel vpn customer(final destination) connected via branch office doesn't need to any thing in their end. Once I'll add route 0.0.0.0/0:0 in existing ipsec tunnel from HQ to branch office. HQ users should be able to access final destination using branch existing vpn.
Again this change requires in between our HQ and branch ipsec tunnel to route traffic from HQ network to customer( final destination) connected via branch office.
thanks again
emnoc wrote:Yes, ensue you have phase2 proposal and router to the final destination. If you deploy a ipsec phase2 with 0.0.0.0/0:0 and control the route and firewall the HQ should be able to access the final remote site network(s).
Ken Felix
could you please confirm on this
"Once I'll add route 0.0.0.0/0:0 in existing ipsec tunnel phase 2 from HQ to branch office. HQ users should be able to access final destination using branch existing vpn."
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.