I am assuming that you have already created a static route to the
outside for all unknown traffic and also created a security policy for
your wireless subnets from the internal interface to the outside
interface and also enabled NAT for the internal ...
Is this a Fortigate to Fortigate IPsec VPN tunnel? If it is then both
groups and separating the subnets into there own phase two selector
should work? You will also have to create security policies in order for
the traffic to be allowed through the f...