IPsec with local IP different than subnet range.
I have a need for an IPsec tunnel between a remote company to a single vm server.
We have a Fortigate 300D connected to our vmware private cloud.
The local IP used needs to be a specific private IP as picked by the other company.
We have the ipsec tunnel up and running.
We need two ports open (12000 and 12001)
Our internal network is 10.0.0.0/24 The local ipsec IP is 10.209.251.56
I'm not really sure where to start. Any sugestions or hints would be greatly appriciated.
We have the tunnel working. I've created a Virtual IP with: Interface: the named IPSec tunnel Type: Static NAT External IP: 10.209.251.56 (the local ipsec ip address) Mapped IP Adrdess: 10.0.0.60 (the vm's private IP) There are ipv4 policies as created by the ipsec wizard. I've tried to add another one to allow the traffic through to the vm. Incoming Interface: named ipsec Outgoing interface: internal interface (10.0.0.0/24) Source: All (I'll lock down after initial test works) Destination: the named virtual ip: 10.209.251.56->10.0.0.60 Services: named ports 12000 and 12001 I've tried NAT on and off.
What resources should I read or study? Do you hav any ideas, solutions or hints?
Thank you
Mark
