Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hervebesnard
New Contributor

VPN IPsec and NAT (outbound, inbound)

Hello, I' ve define a VPN IPsec between a Site A (with a Funkwerk r230a) and a Site B (with Forigate 110C v5.0). Site A : Only a LAN 192.168.1.0/24, only one server 192.168.1.1 Site B (multiple Vlan): 192.168.100.0/24 for server 192.168.200.0/24 for client From this site, i have a MPLS with networks 192.168.1.0/24 to 192.168.39.0/24. Because of the MPLS, actually it' s not possible to route the request from the site B to the site A. There is no problem with the tunnel, it' s up. I think, that I need a translation from request site A (192.168.1.0/24) to another set of adress (like 10.1.1.0/24) to have no conflict with the MPLS. Actually, I can' t change the network adress on site A. How can I do it ? In the same idea, I need client 192.168.200.0/24 from site B to access server on site A (192.168.1.1). I think it should work if it' s possible to translate outbound, for example 10.1.1.1 to 192.168.1.1. Regards, Herve
Hervé Besnard IT Manager
Hervé Besnard IT Manager
2 REPLIES 2
emnoc
Esteemed Contributor III

Yes you can do this quite easily with interface VPN. You define a Natpool for suite a and VIP for site A using the named interface in you phase1-interface. I would suggest to get away from the 192.168.1.0/24 address space. You will have problem like this and in the future.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
SuperUser
SuperUser

emnoc is right, avoiding the 192.168.[0-2] networks would be wise. But sometimes networks are inherited and cannot be changed easily. Like in this case. I' d like to point you to a recipe from the FortiOS Cookbook, v. 5.0.7, which explains how to achieve this (connecting 2 subnets with overlapping network address ranges). It starts at page 392. Just be sure you use an interface-based (or route-based) VPN, as is the default. You can determine this by looking at System>Network>Interfaces: if you see your phase1 as an interface there, you' re good. If not, recreate the VPN in Interface mode. You can get the docs at http://docs.fortinet.com .
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors