Skip to main content
Mike_P
New Member
May 12, 2020
Question

Dynamic VPN to VIP NAT

  • May 12, 2020
  • 4 replies
  • 10260 views

Hello everyone, Michael here. I am new to Fortinet. I have a Fortigate 30E and I am trying to setup a unique network that my company already has in use on Cisco and Cradlepoint.

 

I will be using a Cisco router as a HUB at our corp office. Each remote Fortinet device will establish a Dynamic VPN to the Cisco router. The default NAT policy will be disabled. The LAN of the Fortinet will have a company registered /24 public network, the same network will be used at every site. The public /24 LAN network needs to NAT to a private /24 VIP network. Each site will have a different private VIP network. The Private VIP network will use the Dynamic VPN to get to the company infrastructure.

 

With the Cisco remote routers we are using ezvpn.

 

Any help would be greatly appreciated.

 

Thanks!

    4 replies

    David_Mary
    New Member
    October 29, 2020
    VPN Interface NAT PoolCreate NAT Pool Interfaces in a VPN

    Use the VPN Interface NAT Pool template for all vEdge routers, to create Network Address Translation (NAT) pools of IP addresses in virtual private networks (VPNs). To configure NAT pool interfaces in a VPN using vManage templates:

    [ol]
  • Create a VPN Interface NAT Pool template to configure Ethernet interface parameters, as described in this article.
  • Create a VPN feature template to configure parameters for a service-side VPN. See the VPN help topic.
  • Optionally, create a data policy to direct data traffic to a service-side NAT. See Create a Device Template.[/ol] Create and Name a VPN Interface NAT Pool Template

    You can open a new VPN Interface NAT Pool template from the Service VPN section of a device template.

    [ol]
  • From the vManage menu, select Configuration > Templates.
  • Click Feature.
  • Click Add Template.
  • Select a vEdge device from the list.
  • From the VPN section, click VPN Interface NATPool.[/ol]

    The VPN Interface NATPool template form displays. The top of the form contains fields for naming the template, and the bottom contains fields for defining VPN Interface NAT Pool parameters.

  • shradha123
    New Member
    December 29, 2020

    , you create a route-based IPsec VPN tunnel, as well as configure both source and destination NAT, to allow transparent communication between two overlapping networks that are located behind different FortiGates.

    In this example, one FortiGate will be referred to as HQ and the other as Branch. They both have 192.168.1.0/24 in use as their internal network (LAN), but both LANs need to be able to communicate to each other through the IPsec tunnel.

     

     

    emnoc
    New Member
    December 29, 2020

     the same network will be used at every site

     

    Why do that  in the 1st place? Since you have to NAT it to begin with? Just stick  rfc1918 in if your NAT'ting the block to begin. K.I.S.S Keep It Straight and Simple. It sounds like you design is flaw or bad from the out the gate or maybe I'm missing something.

     

    On the DYNAMIC VPN, make sure to use  a peer-group per each remote spoke. I.e FQDN or email would be my choice

     

    peer1 == per1.yourdomain.com  --DNS

    peer2== peer2@yourdomain.com   --email

    peer3 == peer3    --DNS or string

     

    Ken Felix

    Ebizfilling111
    Visitor III
    December 2, 2021

    Create NAT Pool Interfaces in a VPN

    Use the VPN Interface NAT Pool template for all vEdge routers, to create Network Address Translation (NAT) pools of IP addresses in virtual private networks (VPNs).
    To configure NAT pool interfaces in a VPN using vManage templates:

    1. Create a VPN Interface NAT Pool template to configure Ethernet interface parameters, as described in this article.
    2. Create a VPN feature template to configure parameters for a service-side VPN. See the VPN help topic.
    3. Optionally, create a data policy to direct data traffic to a service-side NAT. See Create a Device Template.

     

    LLC Incorporation in Delaware, USA

    How to start a Pharmaceutical Business in India

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.