Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rezendecs
New Contributor

Site-to-site IPSec VPN with thirdy party products using private IP address on WAN.

Hi All,

 

   I have a Fortigate and trying do a site-to-site IPSec VPN with a thirdy party equipment.

   This equipment use a private IP address in it's WAN interface (10.x.x.x), delivered by ISP. 

   How can I do to configure this VPN? 

   The option to use dynamic dns doesn't work because the dynamic dns of Fortiguard use the IP of the Wan interface and not the public IP address of my ISP.

   

Regards,

Claudio Rezende

Claudio Rezende
Claudio Rezende
3 REPLIES 3
gschmitt
Valued Contributor

Do you have a static public IP?

Can you enable Port Forwardings on the ISPs device or all ports forwarded to the FortiGate?

rezendecs
New Contributor

@gschmitt,

 

     In side of Fortigate I have static public IP address, but in other side not, and I don't have access to ISP router to forward the traffic to firewall.

 

 

Regards,

Claudio

Claudio Rezende
Claudio Rezende
gschmitt
Valued Contributor

Go to VPN > IPSec > Tunnels

Enter a Name and select Custom VPN Tunnel

IPv4

Static IP Address

Enter the IP Address of the other side

Select the connected interface (usually wan1)

Preshared Key > Enter the key for dialup

Select encryption as needed and the local and remote address

 

On the other side (assuming it's fortigate)

Copy nearly all settings from above but select Dialup User as Remote Gateway

 

Make sure policies and routes on both sides are created or add them if needed.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors