I have an unusual issue that I have to get resolved.
I have a vendor that connects to our Internal IP - call it 10.1.1.1 via policy based vpn tunnel strongswan. That tunnel needs to reach 10.2.2.2 which is on a different VPN tunnel. routes are in place to get that traffic, but the vendor side can't make routes.
Incessance, they want to be able to connect to 10.1.1.50 on their end, and have our end pass that traffic being sent to that IP to 10.2.2.50 on our end. The vendors end has no idea 10.2.2.50 exists. all traffic will need to be translated. I am trying to figure out if a NAT will do that, or if there is a different way?
It will be internal to basically internal forwarding. Or is this not possible?
DNAT will do the job in your case, just make sure that isnt not being used/assign anywhere else.
just make sure that there's a return route for the traffic on 10.2.2.x end or SNAT the traffic of your vendor towards 10.1.1.50>10.2.2.50
User | Count |
---|---|
2592 | |
1380 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.