Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NetJO
New Contributor

IPSEC TUNNEL with NAT

Hi all. I need help to figure out if a configuration is possible and where I'm doing wrong.

Please see the attached scenario. I have fotigate_A and fotigate_B connected with an IPSEC tunnel. The tunnels goes UP. I have some networks behind the fotigates and two of them overlap. I don't need at all to let the overlapping networks to see each other (red networks)

I want the overlapping network behind fortigate_A to see other networks behind fortigate_B and I want to do this performing NAT only at fortigate_A. I want a static one-to-one translation.

So I configured an IP POOL 192.168.240.0/26 that translates 192.168.59.192/26 (fixed port range) When I ping from 192.168.59.193 from behind the fortigate_A, the destination 172.16.23.73 receives the echo request from the translated address 192.168.240.1 and replies. If I ping from the 192.168.59.196, the destination host correctly receives the echo request from the translated address 192.168.240.4 So I can say: Translation works IPSEC tunnel works Routing works

but... If I try the opposite, pinging from the 172.16.23.73 address behind the fortigate_B to the translated address 192.160.240.1 of the host behind the fotigate_A... the ping fails. I can see the echo requests go through the tunnel an arrive to the fortigate_A (diag sniffer packet), but I can't see echo replies.

Where could I be wrong?

Any help is appreciated

Regards

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

With FortiGate, unlike Cisco routers, when you need a static one-to-one NAT for BOTH directions to work, you need to configure a set of a NAT policy (outgoing direction:SNAT) and a VIP (incoming direction:DNAT). In other words, they work independently.

So you need to configure VIP/DNAT to change the destination IP from 192.168.240.x to 192.168.59.x at FGT-A.

andre_marsaioli
New Contributor

I have the same problem. Please, someone solved something like this before?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors