Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hxcsp
New Contributor

Site-To-Site VPN > Multiple Subnets

Hello,

 

I am having an issue with reaching a certain subnet over a VPN tunnel.

 

Site A: 10.50.1.1/24

Site B: 10.0.1.4/16

Phone Network: 172.21.0.0/16

 

Site A and Site B are connected via VPN Tunnel

Site A needs to reach Phone network.

Phone network is reachable via a Gateway at SiteB: 10.0.1.1

 

Currently, Site B can reach the phone network via Static Route.

I have a static route at Site A routing Phone network through the VPN Tunnel Interface.

 

My VPN Tunnel From A to B has two Phase 2 subnets: 10.0.0.0/16 and 172.21.0.0/16

Firewall Policies are in place to allow traffic from 10.50.1.0/24 to 10.0.0.0/16 AND 172.21.0.0/16    and vice versa.

 

When attempting to access the Phone Network from Site A, the trace shows it going out the WAN Interface and not over the VPN tunnel.

Is there something I am doing wrong? Remote sites need to reach the Phone network via Site B's alternate gateway 10.0.1.1.

Thanks in advance.

5 REPLIES 5
emnoc
Esteemed Contributor III

When attempting to access the Phone Network from Site A, the trace shows it going out the WAN Interface and not over the VPN tunnel.

 

check router table

 

cli   get router info rout all

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
MikePruett
Valued Contributor

verify the route on device A is in place.

verify the tunnel has phase 2's in place to allow the traffic

Mike Pruett Fortinet GURU | Fortinet Training Videos
Toshi_Esumi

If routing-table looks correct, I would sniff traffic (diag sniffer packet <INTERFACE> 'host x.x.x.x and icmp' if you're pinging x.x.x.x) after disabling auto-asic-offload on the policy in case your model has asic chips.

hxcsp

Thanks for your replies.

I was able to figure out what the issue was.  NAT was turned on in one of the static routes when it shouldn't have been.

emnoc
Esteemed Contributor III

FWIW:  NAT is a fw-policy function and has nothing todo with a static-route. You don't enable SNAT or even DNAT by just a  static-route.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors