IPsec tunnel from our firewall (Fortigate 100F) to Azure basically works, as soon as we set up NAT or activate NAT rules in Azure, the tunnel breaks down or the traffic does not work. My concern is that we are probably not passing through the NAT range correctly, but I cannot prove this.
Is your NAT address defined in phase2 selector on both ends?
Hi @AUT_Maverick,
Please check phase2 selectors as suggested by AEK. You can also collect ike debugs to see why it is not working. Please refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Understanding-IPsec-iked-debug-logs/ta-p/2...
Regards,
Please review the following document to verify the Tunnel configuration
Your concern is quite understandable. Perhaps the problem is actually related to incorrect NAT range transfer configuration. It is recommended to check the correct NAT settings on both sides of the tunnel and ensure that the NAT range is correctly transmitted through the tunnel. It is also worth paying attention to possible conflicts in network settings and routing settings. If in doubt, you can contact Fortigate or Azure support for further assistance.
User | Count |
---|---|
2047 | |
1170 | |
770 | |
448 | |
340 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.