Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mtellso510
New Contributor II

IPSec VPN with NAT

I am trying to set up an IPSec VPN to a partner that is using an IP range that I already have in use. I know I will need to create a NAT to accomplish this and I want to have this set up on my end. my partner' s range is 10.0.1.0/24 and I am trying to set it up so it looks like 10.1.1.0/24 from my end. Phase 2 is failing because the remote end sees that I have set up 10.1.1.0 instead of what they set up as 10.0.1.0. Does anyone have suggestions as to where I should go to look for the problem?
2 REPLIES 2
Istvan_Takacs_FTNT

The FortiOS handbook has a few pretty good examples for exactly the same scenario. I' d suggest to start at section " How to work with overlapping subnets" . You can download the guide from http://docs.fortinet.com/d/fortigate-fortios-handbook-the-complete-guide
Maury
New Contributor

Dear All, Even if I' m a New member, let me answer to ISTVAN that: ...Even if the link you posted is a good resource, that I' m using too, inside it, there isn' t a clear example of NAT application using VPN as required by MTELLSO. What is required is to have a configuration NAT to be applied on one VPN Gateway only (the one under MTELLSO' s administration). The examples you may found inside the book require to handle the NAT on both VPN Peers. On pages 1684 to 1688 are described the two VPN profiles: routed or policy based, and in both cases you need to setup nat on both Gateways: FortiGate_1 and FortiGate_2. I' m in the same scenario of ISTVAN, and still now have not found a solution for it. I' ve looked on many NAT settings, debugging packets, and flows, without results. The only NAT settings I' ve found to work on my case was at the end " Source NAT" : before to send the packet on the Tunnel interface, I' m able to mask the source, not the destination. .. Due to I' m a " new" with Fortinet I' m sure that I wrong something... so I' ll look for all suggestions and comments that certainly may help us on this case..
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors