Skip to main content
seanbnd
New Member
November 27, 2019
Question

IPSec DNAT

  • November 27, 2019
  • 0 replies
  • 1731 views

I recently replaced a WatchGaurd XTM 5 series firewall with a Fortigate 60e. I'm having issues with one of the tunnels I setting up. I do not have control of the other side of the VPN. Here is my issue: The only way I can get phase2 to connect is by setting the local address to our WAN IP. The tunnel then connects but no traffic can flow through. In the watchgaurd the local address is set to the local subnet, but, it is set to DNAT with the IP being the routers WAN IP address. How can I get the same result on the Fortigate? I'm assuming I have to have the local address set to the local subnet and somehow get phase2 to use the WAN IP to authenticate. I have the IPv4 egress and ingress setup and the static route setup. Any help would be appreciated.