Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
waaalex
New Contributor III

[SOLVED] IPSEC VPN and Internet Access (hub n spokes)

Hello,

We have an Hub n spoke architecture.

Each spoke (3) can ping networks each other (NAT disabled). When NAT enabled on spoke zone to spoke zone, spokes can't ping each other.

 

At this time, Internet access on spoke sites pass throught their Internet connection (WAN interface on each spokes)

We want to pass Internet access throught HUB to manage all Internet Policies from the HUB.

 

Is it possible? 

Thanks.

Regards.

Waaalex.

 

1 Solution
boneyard
Valued Contributor

yes, that is possible.

 

some things to consider.

 

you need to set your default route to the VPN. but dont forget the put a static route to the VPN IP of the hub to the ISP gateway else you loose your connection.

 

your phase2 will have to contain the 0.0.0.0/0 as destination as you will have to encrypt all addresses.

View solution in original post

11 REPLIES 11
waaalex
New Contributor III

@boneyard

 

Thank you very much, i finally understood what to do : 

Summary : 

On the HUB : VPN Phase 2 0.0.0.0/0.0.0.0 local and remote (to adapt if there is several phase 2, 0.0.0.0 for local only)

                     Create a policy ZONE_VPN TO WAN with Internet access allowed (NAT)

ON THE SPOKE : Route to HUB public address through SPOKE ISP

                         VPN Phase 2 0.0.0.0/0.0.0.0 local and remote (to adapt if there is several phase 2, 0.0.0.0 for remote only)

                         Default route to ZONE VPN and Blackhole (admin distance 254 for blackhole)

                         Create a policy LAN to ZONE with ALL access

 

We can deny some VLAN as well.

Thank you very much for help. I m not a network specialist (much more system).

Forti Forever ;)

Regards,

Alex.

boneyard
Valued Contributor

nice, thanks for sharing.

Labels
Top Kudoed Authors