Hi,
I' m currently trying to setup a Fortigate 60D with an IPSec tunnel to one of our external providers. They' ve given me the specific VPN configs, and require us to NAT all traffic to their network to a specific address. I also need to NAT their network behind a local address, so that all of our internal hosts will connect to a single IP in order to connect to this providers server over the tunnel.
So far I' ve got the tunnel up, and traffic going accross it, but I' m having a lot of trouble with the NATing. I' ve also found that under the IPSec monitor in the web config, I can see 2 tunnels at all times under the same name, although only one is able to be brought up. Diag debug of VPN traffic also confirms that there is constant phase1 attempts that go unanswered, despite the tunnel showing as up.
Desired Setup:
- External Provider will only ever see traffic from our network originating from the NAT address they' ve supplied us (150.x.x.229).
- Internal Users will only ever see the providers server as the NAT address we' ve setup (10.136.21.10).
Current Status:
- IPSec tunnel: up
- Ping external server: successful from firewall
- Ping internal NAT from firewall: successful, but it' s not going over the tunnel. Looks like it' s only pinging it' s own interface with a repyl time of 0.2ms.
- Ping internal NAT from host: unsuccessful
Current Config:
IPSec:
- Phase 1 (non-interface mode)
- Phase 2 - Quick Mode Selector
- Source: 150.x.x.229 (provider NAT)
- Dest: 150.x.x.10 (provider server)
Policy:
(1)
srcport: internal
dstport: wan1
srdaddr: 150.x.x.10, 150.x.x.229
dstaddr: 150.x.x.10, 150.x.x.229
action: ipsec
sched/service: all
nat: disabled
(2)
srcport: internal
dstport: wan1
srcaddr: any
dstaddr: VIP (10.136.21.10 -> 150.x.x.229)
action: accept
sched/service: all
Static Routes:
0.0.0.0 wan1 172.16.0.1
150.x.x.10 wan1 172.16.0.1
10.136.30.0 internal 10.136.30.20
<various other internal static routes>
I' ve attempted to setup the IPSec tunnel in Interface mode, but for some reason I can' t get the tunnel up. All other settings are identical, only the Local-gateway is set to the external VPN peer (62.x.x.x). Also note that the ADSL modem should not be an issue, as the tunnel has been established.
Any suggestions or advice would be very much aprpeciated, I' ve dug through multiple resources to try and get this working. This is actually going to be a secondary link, as we already have an identical setup in another office to the same provider (only with a different model firewall).
Cheers,
Mike