Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Site-to-site VPN with internet access passthrough?

So, I have a site-to-site VPN set up, and it' s working great when I want to go from the private network at site A to the private network at site B. No problems at all with the site-to-site VPN setup. Both site A and site B have a public IP address on the WAN1 interface, and the private network on the Internal interface. On the public side of site B' s FortiGate, I have another private network that I can route to from the private network at site B using the default gateway (FortiGate unit). I would like to also allow the private network at site A access to this second private network. I have tried policy based routing and interface based routing, looked at documentation from Fortinet and read examples of VPN to internet based routing here on the forums. Any suggestions?
12 REPLIES 12
rwpatterson
Valued Contributor III

Is this VPN policy or interface mode?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

It is currently in interface mode, using the main IP on WAN1 at each site.
rwpatterson
Valued Contributor III

Cool. On each unit, under the external interface in the lists, open the drop down to the subinterface. There is an option here to give each sub interface an IP address and define the remote IP address as well. Do that making sure they are in the same subnet. Last, in the ' Router > Static' section, route your traffic.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Ah, OK. I will give that a try! Thanks!
Not applicable

I guess I need a little detail on this procedure. I' ve assigned an IP address to each sub interface, but when I go to route traffic from the private side of A to the public side of B, the routes aren' t working.
rwpatterson
Valued Contributor III

You route traffic between the sub interface IP addresses. Pass traffic down thru the tunnel.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

I' ve got the sub-interfaces set up, and I have the static routes configured to allow the private networks at A and B to see each other via the static route (traceroute confirms my config is bouncing off of the sub-interface IP addresses). What I have a problem with is going from private side A, through the VPN tunnel, and out the WAN1 interface on the B side instead of going to the private side. Private A to private B on the " internal" interfaces is working like a charm.
rwpatterson
Valued Contributor III

Route only the subnets you wish to share on the remote side, not 0.0.0.0. The only way the remote side knows about that stuff is from your routing statement. Otherwise it goes out the local door.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

So far I have tried 0.0.0.0, and doing explicit routes for networks. Nothing is working so far, except the private to private side links. I' m thinking I' m going to have to move the FortiGate up a level in the network so I can interface directly a router running OSPF. I' m about out of options on this thing. Traceroutes show that I am making it from B to A, but dying on A when I try to go out to a network off of WAN1.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors