Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
eng_hamed
New Contributor

IPsec VPN Fortigate 100D to Cisco ASA

Dears,

 

i actually facing a problem i am working on establishing an IPsec Connection Between Fortigate (my side) and Cisco ASA (Remote site) i want to Use NAT to Translate my Local Subnets to Proposed Subnets from Remote side my Current LAN Subnets 10.0.0.0/8 shall be translated to 172.19.190.0/255.255.255.0 (VIP Range) Remote subnets 10.162.51.0/255.255.255.224 my problem after Creating the IPsec Phase 1 and 2 connection is up and running but i cant Ping Remote subnets, and remote site can only Ping My firewall IP i configured Policies where inbound: VPN Interface to LAN interface - source (remote Subnets) - Destination (VIP range) Schedule ALL - Services ALL  NAT (disabled) Outbound: LAN interface to VPN interface - source (ALL) - Destination (Remote Subnets) Schedule ALL - Services ALL NAT (enabled) a Static Root made to Remote Subnets. any one knows what missing ? what shall i do ?

5 REPLIES 5
Somashekara_Hanumant

Hello Hamed,

 

On Phase2 tunnel you need to disable the 'use-natip'  command and then set the 'natip'  as 172.19.190.0/255.255.255.0 on the respective firewall policy.

 

make sure you have configured the NAT IP on phase quick mode selectors, for more information, kindly refer the below IPSec admin guide from page number 74 onwards, it talks about Subnet overlapping.

 

http://docs.fortinet.com/uploaded/files/1881/fortigate-ipsec-52.pdf

 

Let us know this helps you to resolve your issue

 

Regards,

Somu

EMEA Technical Support
joshua_m

Hi did you configure static routes on both side?

eng_hamed

Hello yes a static root Created on Both side

eng_hamed

Hello Somu thanks for your answer,

you explination sound resonable, i was asking you you know CLI command to edit already created IPsec to disable use-natip as on file indicates only if am going to create it. or the only reason is to remove and recreate the tunnel again using CLI ? regards Hamed

Somashekara_Hanumant

Hello Hamed,

 

Yes you can disable the use-natip from the cli command on phase2 ipsec tunnel, without deleting the tunnel

 

Hope this helps  you.

 

Cheers,

Somu

EMEA Technical Support
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors