Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FeM_User
New Contributor

Setting a VPN behind two offices with two 30E one behind another router

Hi forum.

I have a question that cannot find the answer even if searching through this forum, and over the network. I have found several discussions here a little bit too far from my configuration so I am opening a new thread.

I have two offices I want to connect via VPN both running Fortigate 30E but in different manner.

The first has the 30E that acts as router+firewall, so the WAN comes inside into the WAN plug and the internal switch is connected to the LAN plug. No problem whatsoever.

The second is placed behind another router (with disabled firewall). Due to the IT manager of the company he did not wanted the 30E to be put in the middle so he connected it behind the telephone company router in the LAN segment having him the address x.x.x.253. No WAN connection, simply the LAN plug inserted into the network segment.

Now the fact. Could such a configuration work ( I mean with no WAN connection of the 30E)

I have already forwarded the UDP port 500+4500 of the router  to the 30E as found in another thread in this forum.

 

Thank You so much.

 

Ferrero

5 REPLIES 5
Toshi_Esumi
SuperUser
SuperUser

You couldn't find this? I would assume many more threads can be found. This is a little old but still legit, yet have good explanation how it would work for NAT-T situation.

https://forum.fortinet.com/tm.aspx?m=129501

 

FeM_User

Toshi Ensumi.

Thank You but I had already found that thread infact there is a mention I have followed where to open UPD 500+4500 port . but there it is mentioned that "The Branch Fortigate WAN interface will be directly connected to a spare LAN interface on the landlord’s NAT router (a Netgear N150 Wireless MODEM Router DGN1000)."

Do I have to configure my Fortigate like that? Putting inside the Fortigate's WAN plug one LAN segment?

What do I have to connect to the Fortigate LAN plugs?

Thank You

 

 

Toshi_Esumi

You set up those forwardings to the FGT at the NetGear, right? That's all you need. And on the FGT side, you just need to make sure NAT-T is configured as in the thread.

FeM_User

Thank You so much.

Really appreciated.

Will try and let you know

ede_pfau

I am running exactly this setup for home office users. One important fact to observe is that the FGT behind a router does not (or not in all cases) obtain a public WAN address. Setting up a site-to-site VPN will then not be possible.

The solution is to set up a dial-up VPN on the 'public' FGT and let the remote FGT dial-in, just like a FortiClient.

My initial worries that FortiGuard updates would not find their way to the 'private' FGT were unfounded.

 

There are examples of this setup in the FortiOS Handbook and probably in the Cookbook also.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors