Skip to main content
robinsonb
Visitor III
June 30, 2022
Question

Connexion fail VPN Fortigate local to Fortigate AWS

  • June 30, 2022
  • 1 reply
  • 1205 views

Hello everyone,

I have a little problem I can not properly configure my local Fortigate VPN on Vmware on my AWS Fortigate. (I followed this: https://docs.fortinet.com/document/fortigate-public-cloud/6.2.0/aws-administration-guide/881566/connecting-a-local-fortigate-to-an-aws-fortigate-via-site-to-site-vpn)

 

Here’s the infrastructure I have 

robinsonb_0-1656593084994.png

On the AWS Fortigate part:

 

robinsonb_1-1656593117197.png

 

robinsonb_2-1656593134328.png

 

robinsonb_3-1656593145117.png

What I get:

 

robinsonb_4-1656593169636.png

 

robinsonb_5-1656593173535.png

 

My security entry group for the fortigate AWS:

 

robinsonb_6-1656593201411.png

(I don’t know if I need to add a route to my subnet)

 

On the Local part Vmware Fortigate:

 

robinsonb_7-1656593283441.png

 

robinsonb_8-1656593287017.png

robinsonb_9-1656593289671.png

What I get:

 

robinsonb_10-1656593331568.png

 

robinsonb_11-1656593336391.png

My local Fortigate can ping my AWS Fortigate.

 

Thank you in advance for your answers

 

1 reply

ssudhakar
Staff
Staff
June 30, 2022

Hi there :

 

From the doc that you have attached, It says that the NAT config on AWS side should be set to This site is behind NAT. I see that you have set it to the remote site is behind NAT. 

 

 https://docs.fortinet.com/document/fortigate-public-cloud/6.2.0/aws-administration-guide/881566/conn...

 
To create a VPN on the AWS FortiGate to the local FortiGate:
  1. For NAT Configuration, select This site is behind NAT. This is the correct configuration since the AWS FortiGate has an elastic IP address. Click Next.

Can you please change it to This site is behind NAT  and see if it works?

 

Thank you,

Hope

robinsonb
robinsonbAuthor
Visitor III
June 30, 2022

Hello Sudhakar,


I think they are mistaken since there are not the same fields to fill on the part
Site behind nat and remote site behind nat.
He explains that it is necessary to fill the incoming interface or this one can only fill it on the part and that the remote site is behind nat.

 

robinsonb_0-1656630036082.png

 

robinsonb_1-1656630041103.pngrobinsonb_2-1656630141627.pngrobinsonb_3-1656630148493.png