Skip to main content
envsion
New Member
May 10, 2018
Question

L2TP/IPSec VPN on Fortigate which is behind a Velocloud Edge Device for SD-WAN

  • May 10, 2018
  • 3 replies
  • 7060 views

Working with a FortiGate that previously had a L2TP/IPSec VPN for Dial-up/Remote users configured. The device now sits behind a Velocloud Edge SD-WAN device and the WAN connection is plugged into it with an uplink from the edge device into WAN1 port on the Fortigate configured with a static LAN IP. Now from the Velocloud, they have setup a 1:1 NAT for the public IP that was once configured on the Fortigate for this traffic {PUBLIC IP --> FORTIGATE through the Velocloud device}, VPN connection fails in Phase 2 based on what I see within the logs. My thoughts, is that I need to add a Secondary IP to the WAN1 configuration on the Fortigate of the public IP address and configure that as the local gateway within the IPSec Tunnel network configuration. Just want to get some thoughts from the community on this.

3 replies

emnoc
New Member
May 10, 2018

The cli cmd diag debug flow and no you should not need a secondary IP. I would ensure NAT-T  is enabled on the FGT

 

 

envsion
envsionAuthor
New Member
May 10, 2018

emnoc wrote:

The cli cmd diag debug flow and no you should not need a secondary IP. I would ensure NAT-T  is enabled on the FGT

 

 

I'll run that command now and post results, I do have NAT Traversal on the Tunnel set to Enabled.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!