Skip to main content
tetelu
New Member
December 11, 2019
Solved

SNAT before IPSEC VPN

  • December 11, 2019
  • 2 replies
  • 4909 views

I have to create an ipsec ssl tunnel with a customer.

Everything seems fine, both phase 1 and phase 2 are up.

But, they asked me to SNAT an internal IP.

Tried to recreate the VPN in policy mode with the same settings - not working.

In phase 2 local subnet is 172.16.5.0/24 and remote is 10.1.43.0/24

They are expectig traffic from 172.16.5.170 to 10.1.43.5 using source nat 10.252.13.1.

Quote:

"As per the IDD traffic should be coming to our firewall from 10.252.13.0/27 subnet. Hence pls configure the source NAT at your end.

Source Address: 172.16.5.170

Destination Address: 10.1.43.5

Source NAT: 10.252.13.1"

 

How should I do this?

 

Thank you!

Best answer by emnoc

Apply the SNAT in the policy and add or create this SNAT ip.addr in the phase2 config if you are not using 0.0.0.0/0 aka quad 0s.

 

Ken Felix

 

2 replies

emnoc
emnocAnswer
New Member
December 11, 2019

Apply the SNAT in the policy and add or create this SNAT ip.addr in the phase2 config if you are not using 0.0.0.0/0 aka quad 0s.

 

Ken Felix

 

tetelu
teteluAuthor
New Member
December 12, 2019

Thanks.

Created in phase 2 and followed the article from the Cookbook with overlapping subnets.

Now it's working!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.