06-24-2016 09:43 AM
I have setup a site-to-site VPN between my ASA and the customers FortiGate. The tunnel comes up successfully, but we can't pass traffic. When I do a packet capture on my ASA, I see the traffic on the ingress port as normal, but on the egress port, the source address gets NAT'd. I have checked all the NAT statements, and there is a NAT Exempt statement from the ingress port to the egress port, and in the VPN configuration,
Solved! Go to Solution.
06-24-2016 10:27 AM
Then your oder of the NAT statements in probably wrong. The dynamic NAT for the outgoing traffic has to be at the end (I put them always in section 3), while the Exemption has to be at the beginning of Section 1.
06-24-2016 10:27 AM
Then your oder of the NAT statements in probably wrong. The dynamic NAT for the outgoing traffic has to be at the end (I put them always in section 3), while the Exemption has to be at the beginning of Section 1.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide