Routing Issue between network segments

Hi everyone


I hope you can help with this. I've attached a crudely drawn diagram which I hope will help.



Main office network: /24

Client office network: /24

Legacy network: /16

Client VPN network: /22


There are two issues that have me scratching my head.


  1. Legacy cannot reach Frankfurt
  2. Client VPN cannot reach Frankfurt

Client Office Network has a core switch with an IP address of All traffic goes out via the Checkpoint. Should the default gateway of this switch be the Checkpoint Would I need static routes to solve the two issues above?


Any assistance would be gratefully appreciated.



Hi B,

I do not see Frankfurt in the diagram or in the network list. Which site is Frankfurt?



Many thanks for your response.


Many apologies, Frankfurt is /24


I would say for your client network the core switch default would indeed the checkpoint however for you client vpn then they should be routed via the vpn tunnel and not the checkpoint nexthop.

kind regards

is the VPN built between the ASA and the Checkpoint ? What reachability do you have, where do traceroutes stop ? It is hard to pinpoint the issue without seeing the configs of your devices, can you post those ?

Thank you everyone for your feedback so far.


I've attached a further (hopefully clearer) diagram. Please see Diagram 1a. This time, I've also added routes that I currently have configured on each device.


Routes on Vodafone router:     


Routes on the Core switch:         


Routes on Checkpoint:      UGHD 0 0 0 External                     U 0 0 0 External                        U 0 0 0 Internal           UGD 0 0 0 External                       UGD 0 0 0 Internal                          UGD 0 0 0 Internal                             UGD 0 0 0 External


The problem:

Users on /16 are unable to access the /16 network. Diagram 1b shows a traceroute from to It times out after hitting


Access the other way works fine. Users on /16 can access /16 fine but the traceroute looks odd to me. It can be seen in Diagram 1c.


Would you be able to review the routes I currently have in place and confirm where I'm going wrong please? I'd like to clarify that the routes I currently have in place are correct. Also, would like assistance on what route I need to add on the Fortigate.


Many thanks in advance.