Skip to main content
thehaw
New Member
May 7, 2021
Question

FGT 60F issue with IPSec behind double NAT

  • May 7, 2021
  • 8 replies
  • 9571 views

Hello All,

 

Sorry if this was already answered.  I'm having a weird issue with a Site to Site VPN where the Fortigate is sitting behind a double NAT (Carrier Grade NAT from the Provider + NAT from an LTE Modem).  

The setup line diagram looks something like this:

(LAN IP 172.X.X.X) Fortigate (Public Static IP)  <-> (Public IP X.X.X.X) Carrier Grade NAT <-> (Private IP 100.X.X.X) Router <-> (Private IP 192.168.2.X) Fortigate <-> (192.168.10.X) LAN Block 

 

I am able to bring up the VPN however I am unable to pass any traffic.  

I am noticing something weird on the IPSec Negotiation (but I'm not sure it matters) where the IKE establishes on port 4501. I know with NAT the alternate port used is 4500 but is it possible that with double NAT port 4501 is chosen?  (just weird).

 

In any case, I am unable to pass traffic in either direction even though the Tunnel is established.  

 

Any suggestions?  

PS.  NAT-T is enabled and has been tested as "enabled" and as "forced" and both options yield the same result. 

 

I'm going to try an upgrade the fortigate behind the NAT to the latest version (just in case this is a known bug) but I wanted to bounce the problem to the list and see if anyone encountered this issue before.

 

Thank you!

Adrian

8 replies

thehaw
thehawAuthor
New Member
May 7, 2021

Forgot to mention, I do have the static Routes in place and the Policies allowing bi-directional traffic to and from the VPN to the LAN Zone.

emnoc
New Member
May 7, 2021

Did you "diag debug flow" and "diag sniffer packet any "host x.x.x.x" where x.x.x.x is the remote gateway?

 

udp.port 4501 does not seem right can you double check that? and was anything change on any of the 2x FGT with regards to ike port that is being used? Execute "diag vpn ike gateway list" and look at the sport-dport for the peer.

 

 

BTW CGNAT should not impact you for IKE or ESP, but make sure you have proper ike-KAs setup. I would do something ridiculous like 10-15secs.

 

Ken Felix

 

thehaw
thehawAuthor
New Member
May 7, 2021

Thanks for the suggestion.  I will take a look at them and provide the feedback shortly.  I'm just going through the upgrade of the OS now to make sure it's not a bug in the firmware.  I was on 6.0.6 before and I am going to the latest build of 6.4.5 for now.

Toshi_Esumi
SuperUser
SuperUser
May 7, 2021

I would contact the carrier first to ask if they're changing/filtering UDP 4500.

emnoc
New Member
May 7, 2021

I highly doubt they are changing the dst-port, the src-port can be any port greater than 0 for NAT-T isakmp.

 

Ken Felix

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!