- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPsec VPN tunnel behind NAT devices at both sites
Hello,
I have 2 sites with 2 Fortigates that have both their WANs behind a NAT device. So basically at both sides I have a NAT router attached to the WAN that has a private ip. Both connections have a public static ip. Is it possible to create an IPsec VPN between the two Fortigates?
Many topics have been discussed but I cound not find a specific answer to that. From the routers is of course possible to forward any port to the WAN interface (NAT-T UDP 4500 or IPsec UDP 500 for example should be forwarded, from my understanding). But will that be enough?
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would think DDNS or a Dialup tunnel would be the best option.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes I found many article about dialup tunnels when a NAT device is in front of the WAN but I came up with this article from support that seems to solve my problem:
Basically it should be enough to forward the required ports and enable NAT-T. I was able to bring up the tunnel after forwarding to the WAN ports 500 UDP and 4500 UDP but still struggling to forward traffic.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You still need the DDNS @UnderscoresAndDashes suggested if the public IP that your NAT/ISP router gets is not a static IP.
Toshi
Created on ‎02-21-2025 01:05 PM Edited on ‎02-21-2025 01:05 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have both static public IPs and overlapping subnets in the IPsec. Actually it seems to me a policy issue with routing because tunnel is up
