Hi all. I need help to figure out if a configuration is possible and where I'm doing wrong.
Please see the attached scenario. I have fotigate_A and fotigate_B connected with an IPSEC tunnel. The tunnels goes UP. I have some networks behind the fotigates and two of them overlap. I don't need at all to let the overlapping networks to see each other (red networks)
I want the overlapping network behind fortigate_A to see other networks behind fortigate_B and I want to do this performing NAT only at fortigate_A. I want a static one-to-one translation.
So I configured an IP POOL 192.168.240.0/26 that translates 192.168.59.192/26 (fixed port range) When I ping from 192.168.59.193 from behind the fortigate_A, the destination 172.16.23.73 receives the echo request from the translated address 192.168.240.1 and replies. If I ping from the 192.168.59.196, the destination host correctly receives the echo request from the translated address 192.168.240.4 So I can say: Translation works IPSEC tunnel works Routing works
but... If I try the opposite, pinging from the 172.16.23.73 address behind the fortigate_B to the translated address 192.160.240.1 of the host behind the fotigate_A... the ping fails. I can see the echo requests go through the tunnel an arrive to the fortigate_A (diag sniffer packet), but I can't see echo replies.
Where could I be wrong?
Any help is appreciated
Regards
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
With FortiGate, unlike Cisco routers, when you need a static one-to-one NAT for BOTH directions to work, you need to configure a set of a NAT policy (outgoing direction:SNAT) and a VIP (incoming direction:DNAT). In other words, they work independently.
So you need to configure VIP/DNAT to change the destination IP from 192.168.240.x to 192.168.59.x at FGT-A.
I have the same problem. Please, someone solved something like this before?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.