cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to pass an only IP between VPN Site-to-site vs Fortinet

Highlighted
Conversationalist

How to pass an only IP between VPN Site-to-site vs Fortinet

Hi community

 

I've a problem with VPN non-meraki vs Fortinet.

 

I need pass only IP to match with Forti, but meraki only allows pass subnets, no IPs, and I don't knwo how do to fix that.

 

RegardsCaptura.PNG

8 REPLIES 8
Highlighted
Kind of a big deal

Re: How to pass an only IP between VPN Site-to-site vs Fortinet

Pass the entire subnet, then setup a site-to-site VPN firewall rule to only allow traffic between the authorized IP addresses.

 

Note that it LOOKS like there's an inbound firewall section, but there's not. There's only outbound rules.

Highlighted
Conversationalist

Re: How to pass an only IP between VPN Site-to-site vs Fortinet

Hi dear Nash.

 

Thanks for your request, but the problem is with the Fortinet, because it has not change this, it send only an IP, not a subnet.

 

Regards

Highlighted
Kind of a big deal

Re: How to pass an only IP between VPN Site-to-site vs Fortinet

The Fortinet will need to send the full subnet in order for the tunnel to come up. Sorry. 😕 It's a real bummer, and not as secure/granular as I would like.

Highlighted
Conversationalist

Re: How to pass an only IP between VPN Site-to-site vs Fortinet

Hi Nash.

 

Thanks for all.

 

I'll call to Fortinet.

 

Regards

Highlighted
Kind of a big deal

Re: How to pass an only IP between VPN Site-to-site vs Fortinet

What do you mean by "only an IP". You can setup tunnels with (one or multiple) /32 subnets which are a single IP?

Highlighted
Kind of a big deal

Re: How to pass an only IP between VPN Site-to-site vs Fortinet

@BrechtSchamp The Meraki end will send its full subnet, won't it? Remote end can totally be a /32.

 

I think I was assuming that @ocuevas wanted to send only a single /32 IP from the Meraki end to the Fortigate end.

Highlighted
Kind of a big deal

Re: How to pass an only IP between VPN Site-to-site vs Fortinet

Ah yes I see. I forgot that the local subnet isn't specified in the configuration but rather automatically used.

Here to help

Re: How to pass an only IP between VPN Site-to-site vs Fortinet

I would contact Fortinet and ask them what they would suggest.

Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.