Skip to main content
morana
New Member
May 3, 2024
Question

fortigate ipsec s2s VPN with starlink ?

  • May 3, 2024
  • 3 replies
  • 8393 views

hello every one .

recently we faced a problem with fortigate s2s with ADSL connections but , we solved it by changing PORT number and they are working great . thanks for all of you for helping .

 

the currrent config for SITE A and SITE B is as following :

site A: ADSL router ---> fortigate >vpn>IPSEC >site to site  > DDNS B >status : UP and can reach site B network

site B:ADSL router ---->fortigate >vpn>IPSEC >site to site   > DDNS A  >status : UP  and can reach site A network

 

Now , We are facing new problem which is  :

SITE A : As it is with above installation and configuration .

SITE B: changed from ADSL connection to star**bleep** connection and became lik this :

 

site B:Starlink router  ---->fortigate >vpn>IPSEC >site to site   > DDNS A  >status : Down Tunnel not Connected

.

i know there is NO port forwarding in starlink router and it is using CGNAT unlike ADSL .

i want to know how to solve this problem with the same configuration for both fortigate .

Do i need pfsens in site B to be in between :

Starlink--> pfsens ----(wireguard)---> fortigate -->etc ..

 

Or any another solutions ???

 

Thanks

 

 

3 replies

morana
moranaAuthor
New Member
May 3, 2024

thanks for the like , i will try that tomorrow and give u feedback...

Toshi_Esumi
SuperUser
SuperUser
May 3, 2024

As @AEK showed, at least Site-B (Starlink) side should be able to initiate the tunnel to Site-A with agressive mode/dialup. But you mentioned "changing port". What exactly did you change.

 

Toshi

morana
moranaAuthor
New Member
May 3, 2024

hello man

NOT port i mean DNS protocol .

believe me i don't know what i am doing i was just playing around ....

under DNS protocol there is an option  :

(DNS UDP/53 protocol ) i enabled it. then it works directly ...

Toshi_Esumi
SuperUser
SuperUser
May 3, 2024

Ok. Did the Site-A FGT get the public IP DDNS A is showing?

Toshi

morana
moranaAuthor
New Member
May 3, 2024

Yes , both showing now ?!

i did something horrible in both routers to make the public IP works !! if the company knows , i will be kicked out  ...

Toshi_Esumi
SuperUser
SuperUser
May 3, 2024

Then it should work.

morana
moranaAuthor
New Member
May 4, 2024

OK helpful friend

what i understand is this

first ,Site A fortiguard DDNS should be Enabled . then

 i am using wizard  i should do the following :

Site A VPN>ipsec >tunnel >convert to custom tunnel >network edit : then i have to change

REmote Gateway : to Dailup user

authentication       : aggressive

update and save ..

and the rest no need for anything else to change here ?

 

second site B fortiguard DDNS should be disabled no need as long as ,it will be dial up  .

then :change to

remote gateway : siteA DDNS

update and save ..

no need for anything else ?

if that's all what i need , then i will give it a try and feedback u ASAP .

 

--------------------------------