Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RB_01_20
New Contributor

Help Needed: IPsec VPN Between NAT and Transparent FortiGates + Inter-Branch Communication

Hi Fortinet Community,

I'm setting up a network with three FortiGates and need help configuring IPsec VPNs and inter-site communication. Here's the setup:


:small_blue_diamond: Topology Overview:

  • HQ FortiGate: NAT mode, connected to ISP via L3 link

  • Branch1 FortiGate: Transparent mode

  • Factory FortiGate: Transparent mode

  • All sites are connected over Layer 2 links

  • DHCP for both branches comes from HQ


:small_blue_diamond: Network Details:

Site Device Role Subnet Assigned
HQNAT mode FortiGate10.10.10.0/24 (LAN)
Branch1Transparent FortiGate192.168.100.0/24 (via DHCP)
FactoryTransparent FortiGate192.168.101.0/24 (via DHCP)
  • HQ Server1: 192.168.100.1 (needs to be accessed by Branch1 PCs)

  • HQ Server2: 192.168.101.1 (needs to be accessed by Factory PCs)

  • All branch PCs should also have access to HQ LAN (10.10.10.0/24)


:question_mark: What I Need Help With:

  1. How to configure IPsec VPN tunnels:

    • Between HQ and Branch1

    • Between HQ and Factory

    • Note: Branch1 and Factory are using transparent mode FortiGates

  2. How to allow the following communications:

    • Branch1 PCs → HQ Server1 (192.168.100.1)

    • Factory PCs → HQ Server2 (192.168.101.1)

    • Both branch networks → HQ LAN (10.10.10.0/24)

  3. Best practices for routing, policies, interface assignment (since two devices are in transparent mode), and any VLAN or zone suggestions for easier policy control. FortiGate 

Rabindra Gauli
Rabindra Gauli
1 REPLY 1
ezhupa
Staff
Staff

Hello,

 

A combination of the below 2 KB articles should work.

For FGT operating in NAT mode
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-VPN-Site-to-Site-between/...
For FGT operating in Transparent mode:
https://community.fortinet.com/t5/FortiGate/Technical-Note-IPSec-VPN-between-FortiGate-in-Transparen...

Hope this helps!


Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors