VIP over IPsec VPN to a remote resource
Hi everyone,
on our FortiGate firewall we have a remote site (AWS cloud) reachable via Direct Connect and IPsec VPN.
All traffic related to private networks flows through the Direct Connect connection. Only Internet traffic flows through the IPsec VPN.
A resource on the remote site needs to be exposed to the Internet for FTPS traffic. I have configured routing, policy routing, and used a VIP. However, if I don’t enable NAT in the firewall policy that allows incoming traffic, the sessions time out. When I enable NAT, FortiGate performs source NAT using a private IP address, and I have no idea where it’s coming from.
My doubt is that the remote resource will see the traffic incoming from a private IP address instead of the public IP and the flow will not work.
Am I missing something in the configuration?
Thanks for the support.
