Skip to main content
andrew737
New Member
January 7, 2019
Question

IPsec with MPLS connection

  • January 7, 2019
  • 0 replies
  • 1901 views

Goodmorning everyone!

I'll try to describe my problem as clearly as possible.

Our ISP gave us an MPLS connection for two different locations, with a 172.16.0.1/17 split. 

Each location has a Fortigate firewall, and now i'm setting up the first one (Fortigate 300D).

The WAN interface retrieve an ip from the ISP (which is a private ip, since the mpls), and let my "Internal" interface to access the internet. Now I need to set an IPsec with our farmserv (310B firewall), which is NOT in inside the mpls, but I can't figure out which IP I should use in the ipsec configuration.My IPS also gave us some pubblic ip, but how can the 310B see the 300D, through the mpls?

I tried setting up a VIP on the 300D, using the WAN interface, mapping one of my pubblic ip to the fortigate ip address (I know it's unsafe, but I'm just testing, there's nothing else behind the fortigate, beside my pc). I can access the configuration page of my fortigate through the public ip, but if I try to create an IPsec using that pubblic ip, nothing happen when I "Bring up" the tunnel. What am I doing wrong?

Thanks, and greetings from Italy!

 

Andrea

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!