Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
v20100
New Contributor III

routing wifi traffic for site to site VPN

Hi

 

On the Fortigates we have about 90 site to site VPN links. The 'source' address is one of our subnet on the LAN interface

We also have a Wifi WLAN with 321C access points connected via a Fortiswitch connected directly to the Fortigates

We would like to be able to connect from the Wifi onto each of the 90 VPN sites.

 

However, it is nearly impossible to communicate to the 90 different VPN partners to add a subnet to the encryption domain, so cannot really modify the VPN settings for each link.

 

I thought of reserving one IP address on our lan to hide the Wifi traffic behind it, when trying to access the VPN sites, but the security only allows 1 outgoing interface.

We are using static routes.

 

Is there a way to achieve this?

 

Thanks in advance 

11 REPLIES 11
v20100
New Contributor III

Thanks Ede

I will investigate this option. Slightly outside my comfort zone in terms on my technical knowledge but will give it a go.

On parallel, we have started contacted some of our partners and will slowly make change for their VPN link. Time consuming and a lengthy process, but safer and works!

brycemd

v20100 wrote:

I found how to create a zone, but it only show the physical interfaces members, so cannot add the 90 VPN tunnels!

 

You can't add interfaces to Zones if they have current policies. Since after it's in a zone you can't have a policy that references that single interface anymore, it would need to reference the Zone instead. It's all or nothing.

 

So if you want to go the Zone route, you need to delete any policy that references all 90 of the tunnels.

 

Obviously, if this is something you want to do, test it out with one or two in the Zone first before dismantling everything.

Labels
Top Kudoed Authors