Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CFSC
New Contributor

VPN tunnel go to another VPN site

We have 2 sites (SiteA & SiteB) that have 2 VPN tunnels with HQ. e.g.:

  SiteA ---- HQ ---- SiteB

Now I can access to HQ on site A and access to HQ on siteB.

Can I access to SiteB devices on SiteA?

1 Solution
kaman
Staff
Staff

Hi CFSC,

Yes, you can access SiteB devices from SiteA through HQ, but it requires configuration on all three FortiGate firewalls (SiteA, HQ, SiteB) to allow inter-site routing over the VPN tunnels.


Please refer to the document below on how to configure a redundant hub‑and‑spoke IPsec VPN topology, which is exactly the setup you need to enable traffic between Site A and Site B via the HQ FortiGate.

https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/755287/redundant-hub-and-spo...


https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/853412/ipsec-vpn-wizard-hub-and-spoke-ad...


If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

View solution in original post

1 REPLY 1
kaman
Staff
Staff

Hi CFSC,

Yes, you can access SiteB devices from SiteA through HQ, but it requires configuration on all three FortiGate firewalls (SiteA, HQ, SiteB) to allow inter-site routing over the VPN tunnels.


Please refer to the document below on how to configure a redundant hub‑and‑spoke IPsec VPN topology, which is exactly the setup you need to enable traffic between Site A and Site B via the HQ FortiGate.

https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/755287/redundant-hub-and-spo...


https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/853412/ipsec-vpn-wizard-hub-and-spoke-ad...


If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors