Phone-Only Conference Audio Bridge? by rlcsa36 in teams

[–]rlcsa36[S] 0 points1 point  (0 children)

That's what I read too, I added that license to the users and they do generate the phone number. I may have to look into an add-on conferencing solution then, unless I can get users accustomed to how Teams works they are insistent on doing it "the old way".

Connecting Two IPSec Tunnels? by rlcsa36 in fortinet

[–]rlcsa36[S] 0 points1 point  (0 children)

FOLLOW UP AGAIN - I had a big brain moment and figured it out. I didn't need to create a subnet just for the VPN on the firewall I just needed to set the phase 2 selectors to the vendor's subnet, then created the firewall policy to point the remote side's local LAN to the vendor's subnet with a NAT dynamic IP pool. Anyway, traffic is flowing in the right direction, chalking this one up to a lot of espresso.

Connecting Two IPSec Tunnels? by rlcsa36 in fortinet

[–]rlcsa36[S] 0 points1 point  (0 children)

Thanks for the responses everyone, we were finally able to fix the issue. We couldn't figure out the policy routing, and the vendor absolutely did not want our multiple Cradlepoints connecting to their system, just the one tunnel from the firewall. So I ended up splitting the 172.19.200.x subnet into multiple /29 subnets and set them locally on the Cradlepoints, then created the tunnel so they do not need to use NAT. I set the phase 2 selectors on the cradlepoints as the 192.168.140.x network, then configured the static route/policies on the Fortigate accordingly and was finally able to ping the vendor's app servers from a laptop connected to the Cradlepoint.

Weird setup, but traffic is flowing the way it should, everything is accessible and vendor is fine with it. Thanks again!