Use of NAT with VPNs
Being a Cisc0 ASA man for years, I am new to Fortigate,I have just configured my first Site-to-Site VPN.
I had to use NAT to hide the real remote site IP from Local. Traffic can be initiated from either end.
this is the requirements
local 10.50.0.0/24(local) to 10.150.34.0/24(remote-NAT) NATed to172.18.36.0/24(Remote) on Fortigate
so tunnel comes up ok using Local to Remote.
Firewall rules
outbound Local to Remote-NAT( using virtual IP to translate to Remote)
inbound Remote to Local ( using IP pools to translate to Remote-NAT)
This all works, but my question is
On Cisco you only require one NAT rule which will cover both inbound and outbound.
but it looks like on Fortigate I need two one defined in virtual IP and the other in IP pools.
AM I doing something wrong?
