Dears,
i actually facing a problem i am working on establishing an IPsec Connection Between Fortigate (my side) and Cisco ASA (Remote site) i want to Use NAT to Translate my Local Subnets to Proposed Subnets from Remote side my Current LAN Subnets 10.0.0.0/8 shall be translated to 172.19.190.0/255.255.255.0 (VIP Range) Remote subnets 10.162.51.0/255.255.255.224 my problem after Creating the IPsec Phase 1 and 2 connection is up and running but i cant Ping Remote subnets, and remote site can only Ping My firewall IP i configured Policies where inbound: VPN Interface to LAN interface - source (remote Subnets) - Destination (VIP range) Schedule ALL - Services ALL NAT (disabled) Outbound: LAN interface to VPN interface - source (ALL) - Destination (Remote Subnets) Schedule ALL - Services ALL NAT (enabled) a Static Root made to Remote Subnets. any one knows what missing ? what shall i do ?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Hamed,
On Phase2 tunnel you need to disable the 'use-natip' command and then set the 'natip' as 172.19.190.0/255.255.255.0 on the respective firewall policy.
make sure you have configured the NAT IP on phase quick mode selectors, for more information, kindly refer the below IPSec admin guide from page number 74 onwards, it talks about Subnet overlapping.
http://docs.fortinet.com/uploaded/files/1881/fortigate-ipsec-52.pdf
Let us know this helps you to resolve your issue
Regards,
Somu
Hi did you configure static routes on both side?
Hello yes a static root Created on Both side
Hello Somu thanks for your answer,
you explination sound resonable, i was asking you you know CLI command to edit already created IPsec to disable use-natip as on file indicates only if am going to create it. or the only reason is to remove and recreate the tunnel again using CLI ? regards Hamed
Hello Hamed,
Yes you can disable the use-natip from the cli command on phase2 ipsec tunnel, without deleting the tunnel
Hope this helps you.
Cheers,
Somu
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.