Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mncomputerguy
New Contributor

Site to Site IPSEC VPN with Nat

I have a internal network that connects via ipsec vpn to an outside vendor. They required us to nat our internal network to public ip address which wasnt an issue. so right now the vpn tunnel looks like this (8.8.8.8 is our fake public ip address for the sake of discussion) 192.168.25.0/24 --->8.8.8.8 ------------------------> 172.16.0.0/28 (they use public ip' s as well) Now the vendor needs to access an internal device on our network via the public address/vpn 172.16.0.0/28 ----------------> 8.8.8.8:445 ->192.168.25.25:445 Is it possible to do some sort of VPN/PAT to make this work?
1 REPLY 1
emnoc
Esteemed Contributor III

Yes you can, you can create a VIP if your using a route-based vpn ( phase1-interface ). Since the interface is a " interface" you select it when you define the VIP. If not clear the FGT2 is my vpn ipsec-interface

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors