Hello,
I am having an issue with reaching a certain subnet over a VPN tunnel.
Site A: 10.50.1.1/24
Site B: 10.0.1.4/16
Phone Network: 172.21.0.0/16
Site A and Site B are connected via VPN Tunnel
Site A needs to reach Phone network.
Phone network is reachable via a Gateway at SiteB: 10.0.1.1
Currently, Site B can reach the phone network via Static Route.
I have a static route at Site A routing Phone network through the VPN Tunnel Interface.
My VPN Tunnel From A to B has two Phase 2 subnets: 10.0.0.0/16 and 172.21.0.0/16
Firewall Policies are in place to allow traffic from 10.50.1.0/24 to 10.0.0.0/16 AND 172.21.0.0/16 and vice versa.
When attempting to access the Phone Network from Site A, the trace shows it going out the WAN Interface and not over the VPN tunnel.
Is there something I am doing wrong? Remote sites need to reach the Phone network via Site B's alternate gateway 10.0.1.1.
Thanks in advance.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
When attempting to access the Phone Network from Site A, the trace shows it going out the WAN Interface and not over the VPN tunnel.
check router table
cli get router info rout all
PCNSE
NSE
StrongSwan
verify the route on device A is in place.
verify the tunnel has phase 2's in place to allow the traffic
Mike Pruett
If routing-table looks correct, I would sniff traffic (diag sniffer packet <INTERFACE> 'host x.x.x.x and icmp' if you're pinging x.x.x.x) after disabling auto-asic-offload on the policy in case your model has asic chips.
Thanks for your replies.
I was able to figure out what the issue was. NAT was turned on in one of the static routes when it shouldn't have been.
FWIW: NAT is a fw-policy function and has nothing todo with a static-route. You don't enable SNAT or even DNAT by just a static-route.
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.