Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bigneo7
New Contributor II

IPSec Site to Site Connection

Hi,

 

How to connect branch office which is the firewall is behind router? 

Branch office WAN using local ip, while router using public ip

1 Solution
enasrullayev
New Contributor

Hello!

 

1. You must configure NAT to change incoming public ip to your firewalls ip which will be responsible for IPSec connection.

2. On the other Site while configuring you will have to enable NAT Traversal (which will tell to the firewall that you will be connecting to the NAT ed private ip address).

3. Don't use AH (authentication header) in this use case. Because of AH encrypts whole ip packet in tunnel mode it wont work.

 

View solution in original post

3 REPLIES 3
enasrullayev
New Contributor

Hello!

 

1. You must configure NAT to change incoming public ip to your firewalls ip which will be responsible for IPSec connection.

2. On the other Site while configuring you will have to enable NAT Traversal (which will tell to the firewall that you will be connecting to the NAT ed private ip address).

3. Don't use AH (authentication header) in this use case. Because of AH encrypts whole ip packet in tunnel mode it wont work.

 

bigneo7

Hello @enasrullayev 

 

NAT will be configure at router?

enasrullayev

Yes.

 

Labels
Top Kudoed Authors