Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
gemechisd
Contributor

Site to Site IPSec VPN with NAT

Hi @All

 

We have a Site to Site IPSec VPN with our partner having FortiGate firewall. We have faced an issue with one of the outbound services. Our source IP is

Local ED: 10.100.3.70
Remote ED: 102.218.49.85
NAT IP: 196.188.175.136

They want our ED to be natted to the NAT IP. When I have done the "fw ctl zdebug + drop | grep 102.218.49.85" attached here with is the error. Can anyone look into it?

Appreciate your help.

0 Kudos
2 Replies
JoSec
Collaborator

Is this route based VPN or Domain based VPN? If domain based, did you add the NAT address to the VPN domain group and is your rule configured to utilize the correct VPN community?

0 Kudos
the_rock
Legend
Legend

Definitely seems like domain based, otherwise FGT enc domain would be 0.0.0.0/0

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events