Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Adrian_James
New Contributor

Should VPN endpoints be able to talk to each other?

Hi all, Sorry if this has been asked but I couldn' t find any info on it. I have a FortiClient to FortiGate IPSec VPN set up and working, with traffic initiated from both directions. Should multiple FortiClient endpoints be able to talk to each other? I also have SSLVPN working as above. Should multiple SSLVPN endpoints be able to talk to each other? Should a FortiClient endpoint be able to talk to an SSLVPN endpoint? The reason is we have a mix of VPN clients connecting and we run a VoIP application. The call setup is fine, but then the call is handed off so that the two endpoints communicate directly. I just want to know if this is possible, at least then I can keep nutting it out. Thanks Adrian
4 REPLIES 4
Adrian_James
New Contributor

I was able to get IPSec FortiClient endpoints to communicate by adding a concentrator and including the phase1 tunnel as a member. Now on to SSLVPN...
Adrian_James
New Contributor

I was able to get SSLVPN spokes to communicate by adding a ssl.interface -> ssl.interface firewall policy with the SSLVPN tunnel IP range as the source and the destination. I was able to get SSLVPN clients to communicate with IPSec clients by adding a ssl.interface -> wan firewall ENCRYPT policy with the SSLVPN tunnel IP range as the source and the IPSec client IP network as the destination. I hope this helps someone. Adrian
abelio

thanks for sharing your tests

regards




/ Abel

regards / Abel
Adrian_James
New Contributor

Also verified by Support that these were the correct things to do.
Labels
Top Kudoed Authors