Skip to main content
RPosselt
New Member
May 13, 2020
Solved

S2S VPN: NAT remote network

  • May 13, 2020
  • 2 replies
  • 2558 views

Hi all,

 

I am setting up a Site-2-site VPN from our hosting center to a customer network. (I only have control of the Fortigate at our end.) However the LAN addresses used on the customer network, is already used by another of our customers.

 

Can I NAT the remote networks addresses in my end? Any description of how to set this up?

I have tried finding info in the Forti Cookbook, but didn't find this scenario.

 

TYIA.

    Best answer by sw2090

    hm I think you can do that by setting the policy that allows the traffic to do dnat either with the ip of the destination iface or an ip pool.

    I do that here with our homeiffice vpns because for one application they need to have an ip in our office lan. So I set the policy on my side to dnat all traffic to this app with an ip out of an ip pool  inside our office lan.

    But dnat with destination interface ip should do the same.

    2 replies

    RPosselt
    RPosseltAuthor
    New Member
    May 19, 2020

    Noone can tell me, if it's even possible?

    sw2090
    SuperUser
    sw2090Answer
    SuperUser
    May 19, 2020

    hm I think you can do that by setting the policy that allows the traffic to do dnat either with the ip of the destination iface or an ip pool.

    I do that here with our homeiffice vpns because for one application they need to have an ip in our office lan. So I set the policy on my side to dnat all traffic to this app with an ip out of an ip pool  inside our office lan.

    But dnat with destination interface ip should do the same.