Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
posemman
New Contributor

IPSec-Site-To-Site (remote ip should be Public ip add or private ip add?)

Hi, I am working on setting up IP sec VPN site to site on each fortigate.

May question is, Do I need to use public ip address(i use ip chicken to see my public ip) as a remote IP? 

 

Or it should be private IP address of fortigate that is connected to WAN1(192.168.254.70)?

 

Default Gateway of fortigate is: 192.168.254.254

3 REPLIES 3
sw2090
Honored Contributor

If you try to connect from the internet you canot se the internal address of WAN1 as it is not available to public and 192.168.0.0 will not be routed anyways.

So you have to use the public ip as remote gw.

Seeing your WAN1 IP I assuem there is some router behind WAN1 that does the internet and the FGT is not doing PPPOE itself there.  In this case you also need to portforward on the router to make IPSec connections reach the FGT.

So you have to forward:

 

500/udp to 192.168.254.70 (IPSec)

4500/udp to 192.168.254.70 (NAT-T)

 

if the opposite site has similar constellation you have to do same way there.

the S2S itself doesn't need to have an IP. It is usually ust used as transport layer and the rest is done by routing and policies (or if needed vxlan).

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
posemman

Hi thank you for your time.

 

I will try your suggestion and gave you an update. 

 

I will set port forwarding of IPSEC and NAT-T port using private IP to PPOE DSL.

Then question, how can I know if this IP(192.168.254.70) do port forwarding already?

 

Another question, how can I easily know my public remote gateway ip address?

sw2090
Honored Contributor

you got me wrong. You need to forward the opposite direction.

Forward the ports from PPPOE DSL external IP to internal IP of your Fortigate that is connected to the router.

 

To check you might do a portscan with e.g. nmap or any portscanner on your external ip of your router.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors