Hello,
I have 2 sites with 2 Fortigates that have both their WANs behind a NAT device. So basically at both sides I have a NAT router attached to the WAN that has a private ip. Both connections have a public static ip. Is it possible to create an IPsec VPN between the two Fortigates?
Many topics have been discussed but I cound not find a specific answer to that. From the routers is of course possible to forward any port to the WAN interface (NAT-T UDP 4500 or IPsec UDP 500 for example should be forwarded, from my understanding). But will that be enough?
I would think DDNS or a Dialup tunnel would be the best option.
Yes I found many article about dialup tunnels when a NAT device is in front of the WAN but I came up with this article from support that seems to solve my problem:
Basically it should be enough to forward the required ports and enable NAT-T. I was able to bring up the tunnel after forwarding to the WAN ports 500 UDP and 4500 UDP but still struggling to forward traffic.
You still need the DDNS @UnderscoresAndDashes suggested if the public IP that your NAT/ISP router gets is not a static IP.
Toshi
Created on 02-21-2025 01:05 PM Edited on 02-21-2025 01:05 PM
I have both static public IPs and overlapping subnets in the IPsec. Actually it seems to me a policy issue with routing because tunnel is up
User | Count |
---|---|
2593 | |
1381 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.