Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tetelu
New Contributor

SNAT before IPSEC VPN

I have to create an ipsec ssl tunnel with a customer.

Everything seems fine, both phase 1 and phase 2 are up.

But, they asked me to SNAT an internal IP.

Tried to recreate the VPN in policy mode with the same settings - not working.

In phase 2 local subnet is 172.16.5.0/24 and remote is 10.1.43.0/24

They are expectig traffic from 172.16.5.170 to 10.1.43.5 using source nat 10.252.13.1.

Quote:

"As per the IDD traffic should be coming to our firewall from 10.252.13.0/27 subnet. Hence pls configure the source NAT at your end.

Source Address: 172.16.5.170

Destination Address: 10.1.43.5

Source NAT: 10.252.13.1"

 

How should I do this?

 

Thank you!

1 Solution
emnoc
Esteemed Contributor III

Apply the SNAT in the policy and add or create this SNAT ip.addr in the phase2 config if you are not using 0.0.0.0/0 aka quad 0s.

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
2 REPLIES 2
emnoc
Esteemed Contributor III

Apply the SNAT in the policy and add or create this SNAT ip.addr in the phase2 config if you are not using 0.0.0.0/0 aka quad 0s.

 

Ken Felix

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
tetelu
New Contributor

Thanks.

Created in phase 2 and followed the article from the Cookbook with overlapping subnets.

Now it's working!

Labels
Top Kudoed Authors