I have two fortigates with a site-to-site VPN connection. This works fine, and is configured like this:
192.168.10.0/24->Fortigate 1->WAN->Internet->WAN->Fortigate 2->192.168.20.0/24
My question is, can a pool be created on Fortigate 1, say a portion of the 192.168.10.0/24 network, for example, 192.168.10.200-250, that incoming connections from remote network 192.168.20.0/24 get mapped to?
End goal is to make devices on 192.168.20.0/24 appear to the server on 192.168.10.0/24 that they are on the same subnet as the server.
Thanks,
-John
Hello @HyTronix ,
Yes, you can create an IP Pool on FortiGate 1 with the range 192.168.10.200-250 and apply it to the VPN policy that allows traffic from 192.168.20.0/24 to 192.168.10.0/24. When enabling NAT in the policy, select the created IP Pool.
Hi @HyTronix,
You can refer to this document for more information https://community.fortinet.com/t5/FortiGate/Technical-Tip-Implement-Source-NAT-for-IPsec-interface/t...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.