- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Site to Site IPSec VPN with NAT
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Site to Site IPSec VPN with NAT
Hi @All
We have a Site to Site IPSec VPN with our partner having FortiGate firewall. We have faced an issue with one of the outbound services. Our source IP is
Local ED: 10.100.3.70
Remote ED: 102.218.49.85
NAT IP: 196.188.175.136
They want our ED to be natted to the NAT IP. When I have done the "fw ctl zdebug + drop | grep 102.218.49.85" attached here with is the error. Can anyone look into it?
Appreciate your help.
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is this route based VPN or Domain based VPN? If domain based, did you add the NAT address to the VPN domain group and is your rule configured to utilize the correct VPN community?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Definitely seems like domain based, otherwise FGT enc domain would be 0.0.0.0/0
