IPsec tunnel from our firewall (Fortigate 100F) to Azure basically works, as soon as we set up NAT or activate NAT rules in Azure, the tunnel breaks down or the traffic does not work. My concern is that we are probably not passing through the NAT range correctly, but I cannot prove this.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Is your NAT address defined in phase2 selector on both ends?
Hi @AUT_Maverick,
Please check phase2 selectors as suggested by AEK. You can also collect ike debugs to see why it is not working. Please refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Understanding-IPsec-iked-debug-logs/ta-p/2...
Regards,
Please review the following document to verify the Tunnel configuration
Your concern is quite understandable. Perhaps the problem is actually related to incorrect NAT range transfer configuration. It is recommended to check the correct NAT settings on both sides of the tunnel and ensure that the NAT range is correctly transmitted through the tunnel. It is also worth paying attention to possible conflicts in network settings and routing settings. If in doubt, you can contact Fortigate or Azure support for further assistance.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.