Skip to main content
anurag48us
New Member
June 3, 2025
Question

How Set VPN Tunnel via SD Wan reach the internet Via tunnel

  • June 3, 2025
  • 1 reply
  • 445 views

Requirement :

Dc Fortinet Firewall :70F

DC Firewall ka WAN IP: 103.62.237.154

Public IP Pool (NAT ke liye): 103.62.237.153/30

Branch Fortinet Firewall: 2 Wan 1 PPPoe WAN1 and 2nd DHCP Wan2

Need Tunnel Between DC aur Branch 

Branch : Fortinet Firewall 40F

Both Tunnel will UP but Traffice will go depend Primary and secondary

Branch office ke ek system ka IP: 103.62.237.158

"What is my IP" site par 103.62.237.158  show 

 

 

Scenario Overview:

You have a Fortinet Firewall deployed at both your Data Center (DC) and Branch Office, and a Site-to-Site VPN tunnel is already established between them. You want internet traffic from a specific system in the branch office to go out via the DC firewall, using a specific public IP (103.62.237.158). That is, when that system browses the internet and checks “What is my IP?”, it should show 103.62.237.158.


Network Information:

1. DC Fortinet Firewall:

  • WAN IP: 103.62.237.154

  • Public IP Pool for NAT: 103.62.237.153/30 → usable IPs:

    • 103.62.237.153 (network)

    • 103.62.237.154 (DC WAN)

    • 103.62.237.155

    • 103.62.237.156

    • You’ve routed: 103.62.237.157/30 to the branch over the tunnel.

2. Branch Fortinet Firewall:

  • Has two WAN links:

    • WAN1: PPPoE

    • WAN2: DHCP

  • Tunnel is UP and established to DC

  • A system in the branch has private IP mapped to public IP: 103.62.237.158


Your Objective:

A system at the branch (with public IP 103.62.237.158) should access the internet via the DC Firewall and must show 103.62.237.158 as the public IP when accessing sites like whatismyip.com.

1 reply

funkylicious
SuperUser
SuperUser
June 3, 2025

sounds like homework.

a hint: policy based routing

"jack of all trades, master of none"