Help with IPSec VPN Source IP
My company installed a new FortiGate 90D in one of our branch offices and I configured it to match our existing FortiGate in another office aside from their external facing IPs and DHCP ranges etc.
Connectivity seems to be fine between sites and from both of our sites and our MS Azure instance but the issue I am having is from the new FortiGate and our Azure LDAP server.
When using a sniffer packet and pinging from the new FortiGate to Azure LDAP it is showing as a source IP that is using the external IP of the router, which gets no ICMP reply. When I do this same test on the currently working FortiGate the IP of the router is translated to the internal IP address, which is allowed.
I compared the configs and everything is the same and I was not able to find anywhere on the working device that is telling it to translate the IP on the IPSec VPN tunnel from the external IP to internal.
The only difference in the two devices is the firmware version, the working one is on 5.2.4 and the new one is using 6.0.13.
The VPN tunnel is up and active and I am able to ping from the new site to the old site, but not directly from the new 90D itself.
Do I just need to set the IP address of the new 90Ds IPSec VPN interface? Currently the working one does not have an IP address set so I'm not quite sure how it is being translated from the External IP -> Internal.
Any advice?
