Skip to main content
random_guy
Explorer
April 30, 2020
Solved

SSL VPN without NAT?

  • April 30, 2020
  • 8 replies
  • 11636 views

Can an SSL VPN  run without NAT?

 

FortiClient 10.200.0.x -> Router 10.0.0.1 -> FGT 10.0.0.10 -> Internal Network 10.0.0.X

 

Running into a problem with internal software trying to connect back to the client but it only sees the client as 10.0.0.10 and not 10.200.0.x. Is it as simple as disable NAT on the policy? Or is there more to it than that?

 

Thanks

Best answer by Toshi_Esumi

If the internal software makes contact to the clients spontaneously, don't forget to add a policy toward ssl.root.

8 replies

rwpatterson
New Member
April 30, 2020

Scratch this entry.

rwpatterson
New Member
April 30, 2020

NAT should only be needed on policies facing the Internet. Any policy that doesn't reach out to public space should be safe to have NAT disabled.

random_guy
Explorer
April 30, 2020

OKay, so I can simply disable NAT on the policies... I'll give it a go.

Toshi_Esumi
SuperUser
SuperUser
April 30, 2020

If the internal software makes contact to the clients spontaneously, don't forget to add a policy toward ssl.root.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!