Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
grecko
New Contributor

Routing across VPN to VLAN

Hello everyone,

 

I hope someone can help with this. I am trying to route traffic across our VPN to a VLAN and back again.  My setup is as follows:

 

SiteA -> Fortigate 100D -

-Port13 connected to VLAN10 on Cisco core switch with switchport mode access.-Port13 is getting an IP address (192.168.210.72) from the DHCP server on VLAN10 (192.168.210.0/24)

-I can ping the DNS server and gateway on VLAN10 from the 100D.

-Ipsec tunnel to 60c at SiteB

 

SiteB -> Fortigate 60C -

-Ipsec tunnel to 100D at SiteA

-I setup a VLAN11 at SiteB to give out IP addresses on 192.168.211.0/24 and set the DNS server address the same as SiteA VLAN10.

-I setup the policies to allow traffic from VLAN11 subnet 192.168.211.0/24 across the IPSec tunnel.

-I can ping the Port13 IP Address (192.168.210.72) on VLAN10 at SiteA over the IPSec tunnel.

-I cannot ping the DNS server or any other IP address on VLAN10 at SiteA from SiteB.

 

I am really just trying to allow SiteB to talk to the VLAN at SiteA.  What would be the best way to do this?  Should Port13 be setup with a Vlan subinterface?  I have tried using a dynamic nat pool to map the traffic from the SiteB with the same subnet as SiteA.  At the same time, I used VIPs for the inbound traffic when I did this but it didn't work.  Please help as I am a wit's end.

 

Thanks...

2 REPLIES 2
gschmitt
Valued Contributor

Did you, on site A, create a policy from the IPSec Tunnel to the VLAN allowing traffic?

Did you include the IPRanges in the Quickmode Selector of the tunnels?

Should Port13 be setup with a Vlan subinterface?

You only ever need VLANs if you plan to have "physically" seperated subnets on the same devices/wire

If you'll only ever use port13 for VLAN10 and nothing else you can do it without a VLAN interface on the fortigate (just make sure you use an untagged port on the switch)

If you use the same port/wire for different uses you need a VLAN interface on it and a tagged switch port.

grecko
New Contributor

I did set a policy to allow traffic from the IPsec tunnel to Port13. That is why I can ping to the IP Address on Vlan at SiteA on the port13 interface. I did not set anything in the quickmode selector, but have static routes set on SiteA to point to SiteB.  I am using tunnel mode at SiteB so I have the IP Addresses set in the policy.

I am going to try adding the VLAN to Port13 at SiteA and seeing if it will pass the traffic to the other IP addresses in the VLAN.  If everything is set correctly, it should be possible to pass traffic from SiteB to SiteA over port13 to the VLAN on that port? 

Labels
Top Kudoed Authors