Hi friends,
I have a scenario where one Fortigate firewall in behind the NAT, means Its WAN interface has private IP which is then NATed with some higher level network device to one Public IP, from internet using the Public IP I can access firewall web interface, but when I configure an IPSec remote access VPN, and try to connect with forticlient VPN and using the firewall's public IP, forticlient is not able to connect with firewall. I have tried from windows and android but same problem, if some one have any idea for solving this issue then kindly guide me.
Thanks
Solved! Go to Solution.
You have to forward 500/UDP (IPSec) and 4500/UDP (NAT-Traversal) from top down.
that means the route with the public ip has to forward that to the private IP of your FGt (or the next hop between FGT and itself), so a connect to 500/UDP or 4500/UDP on the publlic ip can reach your FGT.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
greetings
did you check UDP port is 4500 ?
You have to forward 500/UDP (IPSec) and 4500/UDP (NAT-Traversal) from top down.
that means the route with the public ip has to forward that to the private IP of your FGt (or the next hop between FGT and itself), so a connect to 500/UDP or 4500/UDP on the publlic ip can reach your FGT.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.