Site-to-site IPsec vpn tunnel behind a NAT router
Hi all,
I have very limited exposure and experience configuring firewalls and I'm completely new to using Fortigate products. However part of my new job requires working with and understanding Fortigate firewalls, setting up VPN's etc...so please excuse my ignorance!
I have a basic IPsec VPN question.
I need to configure a site-to-site IPsec vpn tunnel between two sites.
Site 1: Main company HQ site is using a Fortigate 60C. The Fortigate has a public ip on its WAN interface which is directly facing the internet.
Site 2: Branch site will be using a Fortigate 30D. This site is a rented office space which uses an internet connection from the landlord’s network that we have no control of. The Branch Fortigate WAN interface will be directly connected to a spare LAN interface on the landlord’s NAT router (a Netgear N150 Wireless MODEM Router DGN1000).
The purpose of the IPsec VPN is to allow staff at the branch site to be able to access a windows server on the HQ's lan network.
Is it possible to setup the IPsec tunnel even though the branch Fortigate sits behind a NAT router?
It is important that I set this up without making drastic changes (or no changes at all) to the landlord's network. Understandably the landlord is not keen on me making changes to his Netgear router to get the vpn tunnel between the two sites working.
I have looked through the Fortigate support documentation, but could not figure out how to do it, I'm sure it is straight forward as I'm guessing this scenario is not that uncommon. The closet I have come is this video, but it mentions dialup, and I'm not sure it is related to what I want. http://video.fortinet.com/video/102/site-to-site-ipsec-vpn-behind-firewall-nat-device.
I would appreciate any advice.
Many thanks,
Kyza
