Hello All,
We want to connect 2 sites with VPN and allow internal network traffic between them over the tunnel.
+ HQ has Fortigate firewall and is connected to a 5G Internet router with Static Public IP
+ Branch also has a Fortigate firewall and is connected to a 5G Internet router with Static Public IP
We want to connect with Site to Site VPN setup. I have doubt on what IP should we assign to the WAN interface of both HQ and Branch Fortigate firewall, which will be connected to the 5G router lan interface? The internal network at both sites are having their own different single /24 subnet. While configuring Site to Site vpn through wizard, should we select the device is behind NAT?
Please guide and share useful link or video on how it can be achieved.
Thanks,
D
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
If feasible you may consider to switch 5G routers to bridged mode for simplification; then FortiGates will receive public IP addresses. Otherwise port forwarding is required along with enabling NAT traversal.
Hello @abarushka
Thanks for your response. Can we just use any new subnet IP in the WAN interfaces at both end and use the option Fortigate is behind NAT while configuring S2S through the wizard?
Regards,
Hello,
I think that IPsec wizard "Site to Site" -> "This site is behind NAT" (for both units) will work as long as port forwarding is configured properly on both 5G routers.
Hey, it's totally doable! You'll want to assign static IPs to the WAN interfaces of both Fortigate firewalls. As for the wizard, you'll likely need to select the option that the device is behind NAT. I've dealt with similar setups before and found it helpful to follow step-by-step guides. You might find this guide useful: https://routerctrl.com/los-light-blinking-red-on-huawei-router/. It offers some great tips for troubleshooting routers. Good luck with your setup!
Most of 5G/4G routes would have "IP Passthrough" feature (quivalent to "bridge mode" for wired circuit routers/modems). That's what we set up almost all our 5G/4G circuit customers.
Then you can use "No NAT between sites"(static) if those are static IPs on both sides. It would be beneficial when you need to set up VIPs on the IPs in the future.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1665 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.