How to configure ipsec vpn between palo atto and fortigate firewall .
VPN flow is following
Remote Lan (22.214.171.124/24) >>>> Fortigate (192.168.10.2 private ip)>>>>>Cisco router(126.96.36.199/29)>>>>>PaloAlto(188.8.131.52/30-public ip)----Local lan
fortigate firewall is the behind the NATed device that is cisco router and Cisco Router have public ip (184.108.40.206/29) but Fortigate do not have public ip address and they have private ip(220.127.116.11).NATed device is in front of fortigate.
How can we configure for that?
If Cisco router don't have DNAT rule to forward packets arriving to 18.104.22.168 further towards 192.168.10.2 then it makes sense to make Palo to be passive.
"Enable NAT Traversal" will encapsulate IPSec packets into UDP packet. This is needed if NAT is involved.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!