How to configure ipsec vpn

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

How to configure ipsec vpn

L0 Member

How to configure ipsec vpn between palo atto and fortigate firewall .

VPN flow is following

Remote Lan (191.168.1.0/24) >>>>  Fortigate (192.168.10.2 private ip)>>>>>Cisco router(203.1.1.2/29)>>>>>PaloAlto(202.1.1.10/30-public ip)----Local lan

fortigate firewall is the behind the NATed device that is cisco router and Cisco Router have public ip (203.1.1.2/29) but Fortigate do not have public ip address and they have private ip(191.168.10.2).NATed device is in front of fortigate.

 How can we configure for that?

2 REPLIES 2

Cyber Elite
Cyber Elite

Palo side

Raido_Rattameister_0-1695907280629.png

 

If Cisco router don't have DNAT rule to forward packets arriving to 203.1.1.2 further towards 192.168.10.2 then it makes sense to make Palo to be passive.

 

"Enable NAT Traversal" will encapsulate IPSec packets into UDP packet. This is needed if NAT is involved.

Raido_Rattameister_1-1695907339183.png

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite

Hello,

check out @Raido_Rattameister reply. The natted firewall/vpn endpoint needs to have the IP listed as the "Peer Identification" IP address. So point your tunnel at the public IP and the Peer Identification as the VPN endpoint device.

 

Regards,

  • 956 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!