Skip to main content
philippegui2
New Member
May 4, 2018
Question

IP source rewriting with fortigate

  • May 4, 2018
  • 2 replies
  • 3084 views
Hello, I have a fortigate on which I have a VPN that works well. My concern is that a subnet is repeated on both sides, a specific machine on one side must communicate with others on the other side but as his address is repeated these requests are redirected elsewhere. I would like to do a NAT by giving a public IP address to reach and arrived at the firewall I assign a NAT. except that for the return I have to change the source address, how could I do this on a fortigate 200D?

    2 replies

    Dave_Hall
    New Member
    May 4, 2018

    See Site-to-site IPsec VPN with overlapping subnets on the Fortinet Cookbook site.

     

    http://cookbook.fortinet.com/vpn-overlapping-subnets/

    ede_pfau
    SuperUser
    SuperUser
    May 4, 2018

    Yupp, this will cover the means to achieve this.

    Source NAT is done via 'IP pools'. Destination NAT is done via 'VIPs'.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!