Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


cloudyweather

7 posts

Wannabe Geek
+1 received by user: 2


#306966 8-Sep-2023 13:29
Send private message

Hi

 

I have a Fortigate firewall with a Teltonika RUT240 in bridge mode to give the Forti 4G capability.

 

The RUT240 has a Vodafone SIM.

 

I'm trying to establish an IPSec tunnel between this Forti and another at head office.

 

It works if I set the head office to "dial-up", where it accepts IPSec tunnels from anywhere, and relies on the phase1 key for security.

 

It doesn't work if I set the head office Forti to use the DDNS registered address of the 4G connected Forti.

 

The IP accepted when dial-up mode is used at head office is different to the IP the 4G interface gets.

 

 

 

So my questions are:

 

Is this to be expected when using a Vodafone SIM - there's some downstream NAT modifying the IP my head office ultimately sees the IPSec connection coming from?

 

Is there any way, a different plan perhaps, to get around this?

 

 

 

I don't want to use dial-up mode as you can't aggregate dial-up tunnels on a Forti, and my policies and routes to this device have to be duplicated for the 4G backup tunnel.


Filter this topic showing only the reply marked as answer Create new topic
Spyware
3818 posts

Uber Geek
+1 received by user: 1366

Lifetime subscriber

  #3124992 8-Sep-2023 13:37
Send private message

CG-NAT.





Spark Max Fibre using Mikrotik CCR1009-8G-1S-1S+, CRS125-24G-1S, Unifi UAP, U6-Pro, UAP-AC-M-Pro, Apple TV 4K (2022), Apple TV 4K (2017), iPad Air 1st gen, iPad Air 4th gen, iPhone 13, SkyNZ3151 (the white box). If it doesn't move then it's data cabled.




Andib
1396 posts

Uber Geek
+1 received by user: 974

ID Verified
Trusted

  #3125002 8-Sep-2023 14:09
Send private message

You'll need to update your APN. from memory "internet" used to the be one that gave you a public IP





<# 
       .DISCLAIMER
       Anything I post is my own and not the views of my past/present/future employer.
#>


coffeebaron
6304 posts

Uber Geek
+1 received by user: 3567

Trusted
Lifetime subscriber

  #3125054 8-Sep-2023 16:48
Send private message

Is it a FWA SIM or just a regular mobile plan SIM?

 

 





Rural IT and Broadband support.

 

Broadband troubleshooting and master filter installs.
Starlink installer - one month free: https://www.starlink.com/?referral=RC-32845-88860-71 
Wi-Fi and networking
Cel-Fi supply and installer - boost your mobile phone coverage legally

 

Need help in Auckland, Waikato or BoP? Click my email button, or email me direct: [my user name] at geekzonemail dot com




cloudyweather

7 posts

Wannabe Geek
+1 received by user: 2


  #3125806 11-Sep-2023 08:54
Send private message

Andib:

 

You'll need to update your APN. from memory "internet" used to the be one that gave you a public IP

 

 

 

 

Awesome, that's got it working.

 

Thanks!😀


Filter this topic showing only the reply marked as answer Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.