I have configured a site2site vpn for my fortigate devices
main office: fgt200B on 4.0MR1 patch 5 (internal lan:.104.x/22)
remote office: fgt80C on 4.0MR1 patch 2 (internal lan: .1.x/24)
I configured them in route-based.
FGT200B configuration
1) fgt200B->router->static route, Des ip: .1.x/24 device is virtual vpn interface.
2) create a policy route in fgt200b->router->policy route, if internal source .104.x/22-> destination .1.x/24, force traffic to virtual vpn interface, gateway 0.0.0.0.
3) Firewall policy: internal->virtual vpn interface, traffic all to all; virtual vpn interface->internal, traffic all to all
4) in phase 2 of site2site vpn, the source is .104.0/22 dest is .1.0/24
FGT80C configuration
1) fgt80C->router->static route, Des ip: .104.x/22, device is virtual vpn interface.
2) create a policy route in fgt80C->router->policy route, if internal source .1.x/24-> destination .104.x/22, force traffic to virtual vpn interface, gateway 0.0.0.0.
3) Firewall policy: internal->virtual vpn interface, traffic all to all; virtual vpn interface->internal, traffic all to all
4) in phase 2 of site2site vpn, the source is .1.0/24 dest is .104.0/22
Tunnel is up as i can see on the vpn->ipsec->monitor. But when i attempt to ping from internal lan to remote lan, timeout.
So what i miss out?
Luke Low