When we build VPN site to site we defince local and remote subnet, and also there are option to add route.
When we enable the add route option why we still need make static route?
If no static route I'm not able access to the remote subnet.
Solved! Go to Solution.
add-route is mostly used in dial-up environments on the hub side to learn and insert into FIB/RIB from phase-2 selectors
https://docs.fortinet.com/document/fortigate/7.4.7/administration-guide/534155
add-route is mostly used in dial-up environments on the hub side to learn and insert into FIB/RIB from phase-2 selectors
https://docs.fortinet.com/document/fortigate/7.4.7/administration-guide/534155
so the add-route is not suitable for non dial-up vpn connection, right?
Hi, The `add-route` option is primarily used for dynamic (dial-up) VPN connections. It is designed to automatically add routes to the FortiGate routing information base when the dynamic tunnel is negotiated. While it is mainly associated with dial-up VPNs, it can also be configured in both policy-based and route-based IPsec VPNs. However, its primary use case is for dynamic connections where routes need to be dynamically managed.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-add-automatic-route-towards-the-rem...
User | Count |
---|---|
2625 | |
1395 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.