Port forwarding through ipsec tunnel

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Port forwarding through ipsec tunnel

L1 Bithead

Hello,

 

I have two Pa-440's.  One 440 has a public static ip and the other is just dhcp as of right now.     I do a site to site to site vpn working between them.  

 

I setup an original port forward on the public  static ip device to a local host and it worked great.   Now, I moved that host to a subnet on the public dhcp firewall.   I tried switching the port forward to the new ip at the remote location across the tunnel interface,  but it never seems to work.  Is this possible to do?

 

Bryan 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @btolkawfp ,

 

You can modify the same rule to NAT the source IP to 10.10.10.10.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

6 REPLIES 6

Cyber Elite
Cyber Elite

Hi @btolkawfp ,

 

NAT over VPN is definitely possible.

 

  1. Do you have a route pointing to the subnet on the public dhcp firewall to the tunnel interface?
  2. Did you change the destination zone of the NAT policy rule and security policy rule to reflect the change?
  3. Do you see the failed traffic under Monitor > Logs > Traffic?  Many times the log will reveal why it isn't working.

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

1.)  The site to site between firewalls is working

2.)  the destination zone of the port forward is untrust and untrust 

3.) no failed logs ..just says incomplete.

 

the issue is getting the client using the public ip and then natting that request through a vpn tunnel and then back to the original firewall. 

Cyber Elite
Cyber Elite

Of course!

 

You will also need to do a source NAT to a prefix on the public static IP FW so that the return traffic is routed back.  The easiest way to do it is put IP addresses on your tunnel interfaces (one on each side) and source NAT to the tunnel IP.  The prefix on the tunnels can be a /30 or even a /31.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L1 Bithead

ok that makes more sense.. i am still having a hard time visualizing that source nat configuration.  Here is port forward rule.

 

btolkawfp_0-1715092442228.png

 

I added a tunnel interface of 10.10.10.9/30 to the public dhcp firewall and 10.10.10.10/30 to the static firewall 

 

 

 

 

 

Thanks for your help.

 

 

Cyber Elite
Cyber Elite

Hi @btolkawfp ,

 

You can modify the same rule to NAT the source IP to 10.10.10.10.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

thanks got it work..

 

  • 1 accepted solution
  • 668 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!