Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Hindmarsh
New Contributor

VPN Tunnel routing help needed

Hi folks. Please have a look at the attached - I need help with setting up another VPN tunnel to allow clients at the remote 172.27.27.0 subnet to see a third party server 103.15.7.2.156 on the externally managed 172.16.5.5 router.

 

Traffic is fine from 172.16.0.0 to 172.27.27.0 in both directions. No problem from 172.16.0.0. to 103.15.72.156 or anything hanging off 172.16.5.5 from the 172.16.0.0 subnet.

 

I know I need another tunnel at least or to add extra endpoints to the existing tunnel but any routing from 172.27.27.0 stops dead at the local Fortigate.

 

Any help much appreciated - this is doing my head in. Converting from Watchguard to Fortigate was enough :)

 

Thanks

 

 

Glen

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

I assume you have vpn between two FGTs for 172.16.0.0/16<->172.27.27.0/24. You need to add another phase2-interface with 172.27.27.0/24<->103.15.72.156/32 to let it go/come over the tunnel. Both FGTs of course need proper routes for the 103. address. Then the 3rd party router need to have route back to your router for 172.27.27.0/24 to have a returning path.

sw2090
SuperUser
SuperUser

As you say traffic between the both 172.xxx subnets works fine in both directiions and also you can reach the external server from the one of them this is quie fine.

This also means that the routes are there already.

What you need to have is policies on both sides that allow traffic from 172.27.270 to the external Server to allow this traffic.

Probably you might need a host route for the external server's ip on the fortigate in 172.27.27.0 so the FGT knowes where to route packets for that ip.

 

This assumes that the client in 172.27.27.0 who wants to connect to the external server uses the FGT as default gate.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors