Hello,
I have to connect over IPSEC two locations.
Achitecture is looks like below:
SiteA LAN - FGT1 - Router - ISP1 device------ Internet-------- ISP2 device - Router- FGT2 - SiteB LAN
Possible to create IPSec on Fortigtes (some NAT-T )?? If yes, could you please provide some tips how to set ??
Thanks
Hi Ted
In case the router performs NAT then NAT-T is required.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPSec-VPN-NAT-traversal/ta-p/197873
Or just leave it "Enable" for auto.
Hello,
OK, thanks for info that is possible :)
So I will go further and what IP's should I use as remote gateway :)??
For example on FGT1:
Which IP I should use as RemoteGaetway in IPSEC configuration:) ??
Thanks
You put the public IP addresses, i.e.: on FGT1 you put 53.x.x.x and on FGT2 you put 78.x.x.x.
Created on 02-11-2025 06:08 AM Edited on 02-11-2025 06:08 AM
Hello AEK,
hmm, but this terminate me IPSEC on Router2 ??
I mean when on FGT1 I will put 53.x.x.x in IPSEC config - this is IP on Router2 connected to ISP. So something more on Router2 to do to bypass this trafic to FGT2 and then terminate IPSEC tunel (to have IPSEC between FGT1 and FGT2) ??
Thanks
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.