Hi,
we have a new MPLS router in 2 offices and we can reach both sides, BUT we have to configure ALL in the incomming Policy.
Office A: MLPS Router 10.2.2.1 - FG WAN - 10.2.2.2 - LAN 192.168.1.0/24
Office B: MLPS Router 10.2.3.1 - FG WAN - 10.2.3.2 - LAN 192.168.2.0/24
We would like to have the policy like:
Incomming 192.168.1.0/24 and Outgoing 192.168.2.0/24 but it doenst work unless we have ALL for incomming.
I guess we can fix it with including the NAT network 10.2.2.0/24 but is there also another option?
Thanks!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Not sure where the problem is here, or what exactly is not working
These are local IPs and MPLS allows communication between them without NAT.
2 policies for each flow, without NAT should be enough:
10.2.2.1/24 <-> 192.168.1.0/24
10.2.3.1/24 <-> 192.168.2.0/24
and if you want communication between LAN segments, 2* more, still no NAT:
192.168.1.0/24 <-> 192.168.2.0/24
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.