Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

TalAmir
New Contributor

VPN behind a NAT

we have a 60D unit sitting behind a peplink load balancer. the fortinet unit has a 10.0.0.x ip and there's a static route to it from the load balancer. we would like to be able to vpn into that box. we've tried opening all the relevan ipsec and  ssl ports to the unit with no sucess,. even opening ALL ports to it fails to connect from a fortiClient. any ideas on how to make this work?

2 REPLIES 2
Somashekara_Hanumant

Hi,

In order to assist you, kindly capture the packets from the below commands

Session1:

diag debug reset

diag debug disable

diag debug appl ike -1

diag debug enable

Session2:

diag sniff packet any 'host x.x.x.x and (port 500 or port 4500)' 4 0 a

(where x.x.x.x is a forticlient source Public IP address)

Regards,

Somu

EMEA Technical Support
MohaFath1
New Contributor

could you pls provide me with a simple drawing for this situation and I'll do my best to help

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.