Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tecnologie
New Contributor

Vpn IpSec for LAN and DMZ

Hi, I have 110c, I create " classic" Vpn IpSec to connect to server in " LAN" . But I want use this VPN to connetct to server in DMZ, it' s possible? I hope!! Thanks Mirko
17 REPLIES 17
Tecnologie

Thanks again for replay and sorry for delay, but I try some configuration.. I try to change configuration but no, there' s something that I not understand. I' m wrong somthing of stupid..but I do not know where!! I use quick mode with 0.0.0.0/0.0.0.0 for connect correctly LAN->WAN - Encrypt (look upper immage) and I do: - I create (added) a policy DMZ->WAN - ENCRYPT (with the same Phase1 and 2), I try to arrive at server in DMZ but NO GOOD - but if I insert in forticlient the network of LanDMZ, I can arrive (of course) correctly to server in DMZ...but not in LAN - So, I try to create another Phase2 with specific quick mode ip (from ip LAN to ip DMZ) but... does not work. You could give me some suggestions? Thanks!!
ede_pfau
SuperUser
SuperUser

Have you created the second phase2? It belongs into the ENCRYPT policy DMZ->WAN. In the Fclient, add both subnets (internal and DMZ) at the same time and try again.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Tecnologie

>>Have you created the second phase2? It belongs into the ENCRYPT policy DMZ->WAN. Yes another Phase2 with the same Phase1... >>In the Fclient, add both subnets (internal and DMZ) at the same time and try again. Sorry but I don' t undestand, where I add BOTH subnets? In FortiClient I put only one subnet, no? Thank you very very much!!
rwpatterson
Valued Contributor III

ede posted the solution a couple of posts back. Scroll the browser up...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Tecnologie

Ok, i find all... but nothing, there are something wrong but i don' t know what. I try to find another way. thanks everybody!!
ede_pfau
SuperUser
SuperUser

So the new VPN tunnel in interface mode connects, that' s good. Try to keep it simple - don' t use DHCP over IPsec now. Give your client a static IP (or just the one it has, it doesn' t matter). For the tunnel, on the FGT you need: - the VPN phase1 and phase2 definitions the QM selectors should not be ' 0.0.0.0' , fill in the local subnet and the remote (client) subnet -- that' s why you need 2 phase2 for 2 subnets -- - a policy tunnel->internal, or tunnel->DMZ; ANY service; ACCEPT action (!) A temporary route (/32) to the dial-in client will be created automatically. On the Forticlient: - the VPN parameters - one subnet (LAN) entered on the first page - ' Advanced' , add the DMZ subnet as well The ' Dial-in VPN' example in the FortiOS Handbook will work as printed. This is not really magic.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Tecnologie

Yes!! Symply thank yuo very very very much!!!!
ede_pfau
SuperUser
SuperUser

You' re always welcome! Glad it works for you now.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors