Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
willow
New Contributor

InterVlan Routing to a VPN

We have a Third Party that would like to allow us access to a subnet on their system via a Site to Site VPN.

 

There is no need for them to access stuff on our network but they want us to use a small subnet to avoid clashes on their end of the network ( 192.168.255.1 / 24 as an example ) we have set this subnet up as a Vlan and have setup and established a IPSEC Tunnel and the tunnel works if your on aforementioned subnet. 

 

Is there anyway to get a Fortigate FG100 to route traffic from another subnet over this tunnel? I can't create a static or policy route to route traffic to the gateway address 192.168.255.1 as it just complains it's a interface address (well yes )) 


Essentially we want it to take traffic from our vlan(s) and act as a NAT gateway sending stuff over the VPN.

 

In the past we have done this by having another router take traffic out of the main router and pipe it back in via a WAN port. This is a little Jank though and I was hoping for something a bit more elegant. 

1 Solution
sjoshi
Staff
Staff

Hi,

 

Yes you can setup by using IPPOOL so in the lan to tunnel policy enable NAT and select IP pool.

So whatever subnet you configure on the IPPOOL that will be the src IP when the traffic reaches the remote end.

Refer:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-SNAT-with-IP-pool/ta-p/19...

Let us know if this helps.
Salon Raj Joshi

View solution in original post

3 REPLIES 3
sjoshi
Staff
Staff

Hi,

 

Yes you can setup by using IPPOOL so in the lan to tunnel policy enable NAT and select IP pool.

So whatever subnet you configure on the IPPOOL that will be the src IP when the traffic reaches the remote end.

Refer:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-SNAT-with-IP-pool/ta-p/19...

Let us know if this helps.
Salon Raj Joshi
willow
New Contributor

Perfect.

That did the trick, setup an overload pool with a single address of the Fortigate IP for the VPN subnet and then turned on NAT for the Firewall Rule using that address. 

 

Seems to have done the trick :)

sjoshi

Great!!

Let us know if this helps.
Salon Raj Joshi
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors