Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tedew
New Contributor

IPSec and two NAT devices along path

Hello,

I have to connect over IPSEC two locations. 

Achitecture is looks like below:

 

SiteA LAN - FGT1 - Router - ISP1 device------ Internet-------- ISP2 device - Router- FGT2 - SiteB LAN

 

Possible to create IPSec on Fortigtes  (some NAT-T )?? If yes, could you please provide some tips how to set ??

 

Thanks

4 REPLIES 4
AEK
SuperUser
SuperUser

Hi Ted

In case the router performs NAT then NAT-T is required.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPSec-VPN-NAT-traversal/ta-p/197873

Or just leave it "Enable" for auto.

AEK
AEK
tedew
New Contributor

Hello,

OK, thanks for info that is possible :)

So I will go further and what IP's should I use as remote gateway  :)?? 

 

Zrzut ekranu 2025-02-10 231459.png 

 

For example on FGT1:

Which IP I should use as RemoteGaetway in IPSEC configuration:) ?? 

 

 

Thanks

 

 

AEK

You put the public IP addresses, i.e.: on FGT1 you put 53.x.x.x and on FGT2 you put 78.x.x.x.

AEK
AEK
tedew
New Contributor

Hello AEK,

hmm, but this terminate me IPSEC on Router2 ??

I mean when on FGT1 I will put 53.x.x.x in IPSEC config - this is IP on Router2 connected to ISP. So something more on Router2 to do to bypass this trafic to FGT2 and then terminate IPSEC tunel  (to have IPSEC between FGT1 and FGT2) ??

Thanks 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors