NAT packets through ipsec tunnel
Hello ;) , this is my first post and I need some help with configuration. I will try to quickly explain:
On Fortigate1 there is LAN 10.12.0.0/16. Fortigate2 has 10.17.17.0/24 LAN (port1) FGT1 & FGT2 are connected via a IPSec VPN connection and on FGT2 I have second subnet on port2 (192.168.40.0/24) What policy I must add to route traffic from 192.168.40.0/24 to the remote LAN (10.12.0.0/16) on Fortigate1 ? I want to go out from LAN 192.168.40.0/24 on FG2 as IP from pool 10.17.17.0/24 and then into the tunnel to reach LAN 10.12.0.0/16 on FG1. I tried add NAT rule (on FG2) from LAN-192.168.40.0/24 to IPSEC TUNNEL INTERFACE but it's not working. Perhaps because it already exists rule to NAT 192.168.40.0/24 to WAN interface on FG2. P.S. I don't wanna change tunnel addresses on both sides. Users from 192.168.40.0/24 must ping 10.12.0.0/16 addresses without adding static routes on theirs PC.
Please help!
Thanks a lot!
Mike
