Skip to main content
secsupport
New Member
February 11, 2022
Solved

How to establish IPSec between fortigate and PFsense

  • February 11, 2022
  • 1 reply
  • 5576 views

The remote office has Pfsence which is behind the router and has no public ip(wan interface) it's on local subnet of the router, FortiGate is direct with wan interface stati

 

so how we can have IPSec in this scenario 

 

kindly explain 

Best answer by kcheng

Hi, 

 

You will probably need a port forwarding from the router at the remote side to perform NAT from the public IP to the Pfsense behind that router. It would not be possible to form IPSec tunnel if FortiGate does not have route and connectivity towards the remote device. The remote gateway is required to be reachable from FortiGate before IPSec tunnel can be formed.

 

1 reply

kcheng
Staff & Editor
kchengAnswer
Staff & Editor
February 12, 2022

Hi, 

 

You will probably need a port forwarding from the router at the remote side to perform NAT from the public IP to the Pfsense behind that router. It would not be possible to form IPSec tunnel if FortiGate does not have route and connectivity towards the remote device. The remote gateway is required to be reachable from FortiGate before IPSec tunnel can be formed.

 

secsupport
New Member
September 19, 2022

Dear @kcheng I did it successfully but just select the LAN port on pfsense side like we select the WAN interface normally but in this case was different (server-client scenario)