Skip to main content
RB_01_20
New Member
April 29, 2025
Question

Help Needed: IPsec VPN Between NAT and Transparent FortiGates + Inter-Branch Communication

  • April 29, 2025
  • 1 reply
  • 450 views

Hi Fortinet Community,

I'm setting up a network with three FortiGates and need help configuring IPsec VPNs and inter-site communication. Here's the setup:


:small_blue_diamond: Topology Overview:

  • HQ FortiGate: NAT mode, connected to ISP via L3 link

  • Branch1 FortiGate: Transparent mode

  • Factory FortiGate: Transparent mode

  • All sites are connected over Layer 2 links

  • DHCP for both branches comes from HQ


:small_blue_diamond: Network Details:

Site Device Role Subnet Assigned
HQNAT mode FortiGate10.10.10.0/24 (LAN)
Branch1Transparent FortiGate192.168.100.0/24 (via DHCP)
FactoryTransparent FortiGate192.168.101.0/24 (via DHCP)
  • HQ Server1: 192.168.100.1 (needs to be accessed by Branch1 PCs)

  • HQ Server2: 192.168.101.1 (needs to be accessed by Factory PCs)

  • All branch PCs should also have access to HQ LAN (10.10.10.0/24)


:question_mark: What I Need Help With:

  1. How to configure IPsec VPN tunnels:

    • Between HQ and Branch1

    • Between HQ and Factory

    • Note: Branch1 and Factory are using transparent mode FortiGates

  2. How to allow the following communications:

    • Branch1 PCs → HQ Server1 (192.168.100.1)

    • Factory PCs → HQ Server2 (192.168.101.1)

    • Both branch networks → HQ LAN (10.10.10.0/24)

  3. Best practices for routing, policies, interface assignment (since two devices are in transparent mode), and any VLAN or zone suggestions for easier policy control. FortiGate 

1 reply

ezhupa
Staff
Staff
April 29, 2025