i have to same model firewalls i configure site to site IPsec vpn its working fine both sides LAN network accessible everything working fine. i want to all my branch internet traffic going to HO Firewall Gateway branch isp did not use for internet traffic means my branch user internet traffic going out HO Firewall.is it possible if yes please help.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
hello,
yes, this is a common setup (if I understand you correctly). If you want to send all internet bound traffic from branch offices to HQ, then
on the branch FGT:
1- create a static route to the HQ WAN IP, with gateway IP: your ISP, interface: WAN port
2- create a default route pointing to the site-to-site VPN interface (no gateway needed)
3- create a policy to allow all destination IPs to the VPN
on HQ FGT:
1- create a default route to the ISP (will already exist)
2- create a static route to the branch LAN (will already exist)
3- create a policy from branch VPN to WAN interface to allow outbound traffic, ENABLE NAT
Of course, if traffic is flowing, protect it properly with AV, AC etc.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.