Skip to main content
Gman
New Member
August 18, 2015
Question

VPN with local addresses NAT'd to WAN1?

  • August 18, 2015
  • 6 replies
  • 5915 views

Hi

 

I'm trying to migrate from a Cisco VPN router to a Fortigate FW.  There is a VPN already configured which I need to move over to the Fortigate.  The set up is a bit strange.  On the remote end the config is pretty standard, they use a private IP range for their encryption domain.  But on the Fortigate I will have to NAT all the local private IPs to the Fortigate WAN1 IP and then encrypt traffic from WAN1 IP address through the tunnel.  Will this work?  I set up my policy using the wizard but wonder if I will need another policy to do the NAT to WAN1?  Thanks in advance for any advice!

 

Thanks

G

    6 replies

    FortiAdam
    New Member
    August 25, 2015

    Yes you can do that by enabling SNAT with an IP-Pool on your internal > VPN firewall policy.  

     

    The IP Pool you create will need to be configured to use the wan1 IP address.  

     

     

    vjoshi_FTNT
    Staff
    Staff
    August 26, 2015

    Hello,

     

    May I know the firmware version on the device?

     

    Below KB article should help you:

     

    http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=12050

     

    Also, the VPN handbook available at 'docs.fortinet.com' can also happen if it is newer version and the document explains different scenarios.

    Gman
    GmanAuthor
    New Member
    August 28, 2015

    Hi

     

    Thanks for your help.  The firmware version is v5.2.3,build670.

     

    Currently I have a NAT for all users to WAN1 for general Internet access.

    I have created the VPN through the wizard and specified WAN1 as the local subnet and the private network of the remote side as the remote network.  Does that sound right?

     

    Thanks

    FortiAdam
    New Member
    August 28, 2015

    Yes you're on the right track but you need to verify your policy for Lan > VPN has NAT enabled and is using the correct IP-Pool.

     

    I'm not sure if the wizard has the option to set this up but you should be able to easily tweak the settings after using the wizard.

    vjoshi_FTNT
    Staff
    Staff
    August 31, 2015

    Here, in your case, it is many to one NAT. As mentioned in earlier post, make sure you select the IPpool which represents the WAN1 IP which you want the traffic to be natted with in the Firewall policy LAN to VPN

     

    Gman
    GmanAuthor
    New Member
    October 28, 2015

    Hi

    It's been a while since I visited this but I tried to connect up the new Fortigate and this VPN still isn't working!

     

    I have doublechecked the old settings copied over from the Cisco.  I now have two policies configured which are as follows:

     

    Internal->VPN - 'src' = private IPs natted to WAN IP - 'dst' = remote IP network

    WAN1->VPN - 'src' = WAN IP - 'dst' = remote IP network

     

    Tried doing some debugs and all I see is 'sent IKE msg (R-U-THERE-ACK)' sent from my IP to the remote peer?

     

    Anyone have any ideas please?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!