Skip to main content
mass1q
New Member
February 19, 2025
Question

IPsec VPN tunnel behind NAT devices at both sites

  • February 19, 2025
  • 4 replies
  • 2111 views

Hello,

 

I have 2 sites with 2 Fortigates that have both their WANs behind a NAT device. So basically at both sides I have a NAT router attached to the WAN that has a private ip. Both connections have a public static ip. Is it possible to create an IPsec VPN between the two Fortigates?

 

Many topics have been discussed but I cound not find a specific answer to that. From the routers is of course possible to forward any port to the WAN interface (NAT-T UDP 4500 or IPsec UDP 500 for example should be forwarded, from my understanding). But will that be enough?   

4 replies

UnderscoresAndDashes
Explorer
February 21, 2025

I would think DDNS or a Dialup tunnel would be the best option. 

mass1q
mass1qAuthor
New Member
February 21, 2025

Yes I found many article about dialup tunnels when a NAT device is in front of the WAN but I came up with this article from support that seems to solve my problem:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-when-FortiGate-is-behind-NAT/ta-p/336494

 

Basically it should be enough to forward the required ports and enable NAT-T. I was able to bring up the tunnel after forwarding to the WAN ports 500 UDP and 4500 UDP but still struggling to forward traffic.

 

Toshi_Esumi
SuperUser
SuperUser
February 21, 2025

You still need the DDNS @UnderscoresAndDashes suggested if the public IP that your NAT/ISP router gets is not a static IP.

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.