Hello,Have you check the following settings :- Is the VPN SSL subnet is
allowed in the ipsec phase 2 ? - have you created a static route in the
FortiGate in site B and Site C ?Regards
Hello, If the subnetwork 192.168.17.0/25 does not exist phyiscally, it's
only use for the VPN connection ? So, you juste need to modify your
policy :- Source address : Your internal Network 192.168.140.0/24 -
Destination Address : 192.168.17.128/25 -...
Hello,If you don't have many VPN IPSec peers, you can do the following.
We have done the same configuration on few sites :- wan1 is for vpn
ipsec- wan2 is for web surfing. We only use static routing for that.For
web surfing : - Set up the default gat...