FortiGate IPSec VPN NAT

This may be useful when dealing with IPSec VPN between two customers, basically allows you to NAT your source address to one provided by the remote LAN administrator.

Tunnel Mode

config vpn ipsec phase2

edit

set use-natip disable

end

config firewall policy

edit

set natip

end

Interface Mode

Create IP pool Interface = internal

On specific policy…

Enable NAT

Select the IP pool created