Site 2 Site VPN between two FortiGates. Both are behind a router
Hello together,
I have a question and didnt find any solution on the web.
We have two offices. A HQ (Augsburg) and a Branch (Berlin). Both have the same FortiGate 60F.
And both FortiGates are behind a Router. I configured both FortiGates to have a Transit-Network between the Router+Modem and the FortiGate. So both Fortigates can browse the web freely.
Now I want to connect both Firewalls via a IPsec Site to Site VPN.
The Problem is that both Firewalls are behind a NAT (because of the Router/Modem) if I understand that correctly.
But I just cant seem to get the Tunnel working because you can only choose between NAT on the other side, or NAT on this site (In the IPsec Wizard)
Do I need a Connection Broker that is between both sides in the cloud? (Like Azure or something else)
And I should mention that both firewalls have different firmwares, but both are version 6.X.
Also, both Router/Modem have the Firewalls set to EXPOSED HOST.
And I have a working SSL VPN on HQ (Augsburg) for Remote Workers.
Can you please help me?
Best regards,
AdminAnoa