Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

VPN site to site route

When we build VPN site to site we defince local and remote subnet, and also there are option to add route.

When we enable the add route option why we still need make static route?

If no static route I'm not able access to the remote subnet.

1 Solution
funkylicious
SuperUser
SuperUser

add-route is mostly used in dial-up environments on the hub side to learn and insert into FIB/RIB from phase-2 selectors

https://docs.fortinet.com/document/fortigate/7.4.7/administration-guide/534155 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-add-automatic-route-towards-the-rem... 

"jack of all trades, master of none"

View solution in original post

"jack of all trades, master of none"
3 REPLIES 3
funkylicious
SuperUser
SuperUser

add-route is mostly used in dial-up environments on the hub side to learn and insert into FIB/RIB from phase-2 selectors

https://docs.fortinet.com/document/fortigate/7.4.7/administration-guide/534155 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-add-automatic-route-towards-the-rem... 

"jack of all trades, master of none"
"jack of all trades, master of none"
HS08

so the add-route is not suitable for non dial-up vpn connection, right?

hpenmetsa
Staff
Staff

Hi, The `add-route` option is primarily used for dynamic (dial-up) VPN connections. It is designed to automatically add routes to the FortiGate routing information base when the dynamic tunnel is negotiated. While it is mainly associated with dial-up VPNs, it can also be configured in both policy-based and route-based IPsec VPNs. However, its primary use case is for dynamic connections where routes need to be dynamically managed.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-add-automatic-route-towards-the-rem...

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors