Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
drivesafely
New Contributor

Site to Site VPN behind internet router

Hello All,

 

We want to connect 2 sites with VPN and allow internal network traffic between them over the tunnel.

+ HQ has Fortigate firewall and is connected to a 5G Internet router with Static Public IP

+ Branch also has a Fortigate firewall and is connected to a 5G Internet router with Static Public IP

We want to connect with Site to Site VPN setup. I have doubt on what IP should we assign to the WAN interface of both HQ and Branch Fortigate firewall, which will be connected to the 5G router lan interface? The internal network at both sites are having their own different single /24 subnet. While configuring Site to Site vpn through wizard, should we select the device is behind NAT?

Please guide and share useful link or video on how it can be achieved.

Thanks,

D

5 REPLIES 5
abarushka
Staff
Staff

Hello,

 

If feasible you may consider to switch 5G routers to bridged mode for simplification; then FortiGates will receive public IP addresses. Otherwise port forwarding is required along with enabling NAT traversal.

FortiGate
drivesafely
New Contributor

Hello @abarushka 

Thanks for your response. Can we just use any new subnet IP in the WAN interfaces at both end and use the option Fortigate is behind NAT while configuring S2S through the wizard?

Regards,

abarushka

Hello,

 

I think that IPsec wizard "Site to Site" -> "This site is behind NAT" (for both units)  will work as long as port forwarding is configured properly on both 5G routers.

FortiGate
Leakerto
New Contributor

Hey, it's totally doable! You'll want to assign static IPs to the WAN interfaces of both Fortigate firewalls. As for the wizard, you'll likely need to select the option that the device is behind NAT. I've dealt with similar setups before and found it helpful to follow step-by-step guides. You might find this guide useful: https://routerctrl.com/los-light-blinking-red-on-huawei-router/. It offers some great tips for troubleshooting routers. Good luck with your setup!

Toshi_Esumi
SuperUser
SuperUser

Most of 5G/4G routes would have "IP Passthrough" feature (quivalent to "bridge mode" for wired circuit routers/modems). That's what we set up almost all our 5G/4G circuit customers.
Then you can use "No NAT between sites"(static) if those are static IPs on both sides. It would be beneficial when you need to set up VIPs on the IPs in the future.

 

Toshi

Labels
Top Kudoed Authors