Hi
Hoping somebody can help me as I'm going round in circles. We recently replaced a Cisco Firewall. A support company that looks after one of the servers on subnet 10.70.0.* had a site to site VPN to a management VLAN of 10.7.1.*. From there, they would hit a NAT IP, which would translate to the the server IP in the 10.70.0.* network (both forwards and reverse).
The Site to Site VPN to the management VLAN is working fine, but I just cannot get my head around setting up the NAT in the Fortigate. Tried as if it were an external NAT, and that didn't work. Tried adding the server VLAN to the VPN and doing a NAT (even a Zone) and that didn't work. Feel like I'm missing something, but can't find a guide on how to do this. Below is a diagram of what I'm trying to do if it helps?
Many thanks in advance. Dan
Hi Dan
If I understand well, you should use DNAT (VIP).
External: 10.7.1.x
Mapped to: 10.70.0.x
Then the related policy should have the VIP object as destination.
User | Count |
---|---|
2570 | |
1362 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.