IPSEC site to site, virtual IP routing special problem
Hi,
maybe someone has an idea, me not, anymore. :(
Setup
lan port 1, net 172.31.0.0/16 (NAT)
|
(site 1) Fortigate, WAN with public IP (fiber connected)
|
IPSEC site to site
|
(site 2) Fortigate, WAN with public IP (fiber connected)
|
lan port 1, net 10.20.20.0/24 (NAT)
Working / Details
- IPSEC is working fine without any bigger problem so far
- no additional modem / router is between, because of fiber-connection
- computer from site 1 from lan-segment can access computer on site 2 in lan-segment
- all policys to route networks 172.31.0.0/16 and 10.20.20.0/24 between the tunnels are setup by the wizard and working well
Non-Working
- Fortigate CLI on site 1 or site 2 is not able to ping Fortigate on other site, this is quite normal, because PING is disabled on this interface, however, Fortigate is not able to ping any computer in lan-segment on the other site
What I want to
- On site 1 I want to setup a public IP on my WAN interface, using one of the ip-addresses out of our public network, to setup a virtual server, or IP forwarder over NAT to access a computer on site 2. This is because of many IP addresses we have on site 1, but not on site 2. Normal virtual server or IP forwarder on site 1 is working, if destination is inside lan 1 (172.31.0.0/16). It does not work using a destination on site 2 from lan 10.20.20.0/24. Is this caused by the non-working-problem mentioned above? Or is it kind of routing problem, because site 2 is not knowing how to route back to source public ip from site 1?
Any help would be nice from you.
Best and thanks
Ronny
