Vpn tunnel Asa 5505 to fortigate 60c

2013-05-18 Thread akurenath
Hi nanog, I have a fortigate 60c connecting a vpn tunnel to an asa 5505. I have the connection setup,  but it will not connect because unfortunately the isp at the fortigate end decided to give us a 192.168.13/24 address. Now what I'd like to know is if there is any way to get this vpn connecti

Re: Vpn tunnel Asa 5505 to fortigate 60c

2013-05-18 Thread Kenneth McRae
What is the public peer address on the ISP end? On May 18, 2013 8:15 AM, "akurenath" wrote: > Hi nanog, > > I have a fortigate 60c connecting a vpn tunnel to an asa 5505. I have the > connection setup, but it will not connect because unfortunately the isp at > the fortigate end decided to give u

Re: Vpn tunnel Asa 5505 to fortigate 60c

2013-05-18 Thread Fred Reimer
Almost all firewalls support NAT-T, which allows for using a private IP address on the "outside" of the firewall (which is translated to a routable public IP address before it gets on the Internet). You will need UDP 500 (for IKE) and UDP 4500 (for IPsec NAT-T) open, so no devices between the fire