Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

NAT' ing within a VPN tunnel

We have been asked to setup a VPN tunnel between ourselves and a 3rd party to us. They will be providing access to an application over this tunnel. The tunnel is no problem for us to setup however, the internal ip range we currently use is already in use by them at their end or overlaps a current range of theirs. I was wondering if it were possible to NAT traffic inside a tunnel on an F310b so we could use a completely new ip list and then NAT that to our users/servers etc. We both use a 10 range internally and they have asked if we could use a 192 range and then NAT that to our 10 range. We have obviously had thoughts about using VIPS but can VIPS be used inside a VPN tunnel? Any help would be very much appreciated.
20 REPLIES 20
sushil

To me it looks the routing problem for outgoing traffic. If we talk about overlapping subnets then under static route the destination network should be the Mapped external IP range (dummy range smthing 192.168.) instead using real address i.e 10 series.This is valid for both the ends.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors