Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sims
New Contributor III

ipsec vpn cisco phone

Hi,

I have cisco cucm  on Head Office and Branch there is phones also 

cucm server ip is 10.0.2.10 and phones are head office also in the same network . And I want phones in branch also in the same network ( it 10.0.2.10 ) 

Can I achieve these using ipsec vpn 

How can i do that ?

 

second question  based on the below attachment 

 

can I use 0.0.0.0  as local subnets and remote subnets 

 

Thanks 

 

5 REPLIES 5
boneyard
Valued Contributor

that is not possible with IPsec VPN.

 

an IPsec VPN is between different layer 3 networks.

 

if you really want this you need to create a streched layer 2 network (via vxlan or l2tp or such)

 

i would advise you to look into just getting your phones working via layer 3, so allow that the cisco pbx can accept phones in other networks.

sims
New Contributor III

Hi,

Why we need tunnel interface for ipsec  vpn 

Thanks

boneyard
Valued Contributor

do don't need it (there is an alternative), but it is quite useful. easy to route to, easy to built policies.

 

is there a reason you don't want it?

sims
New Contributor III

Hi,

What is the benefit if we add tunnel interface and what are alternative 

Thanks

boneyard
Valued Contributor

you could try a google search yourself also ...

 

benefits for me include

  easy to route to

  easy to built policies

  most common method with FortiGate, meaning most documentation and example

 

the alternative is policy based VPN, see: https://docs.fortinet.com...icy-based-ipsec-tunnel

Labels
Top Kudoed Authors