| Description |
This article explains how to configure Port Forwarding (Virtual IP) for IKE traffic on the FortiGate when having a site-to-site IPsec tunnel terminated on the FortiGate.
Note: For illustration purposes, a private IP is assigned to each interface. |
| Scope | FortiGate. |
| Solution |
To fix this conflict, the 'src-filter' of the Virtual IP object will be used.
In this way, site-to-site between FGT_Primary and FGT_Remote-S2S will be formed, and then inbound IKE from the dialup users (10.47.1.168) will still be forwarded to the internal Dial-up VPN server accordingly.
Note: In the actual scenario, the IPs filtered would be public IP address ranges. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.