SSL VPN port forward from Meraki to Fortinet 60E

msaeed
New here

SSL VPN port forward from Meraki to Fortinet 60E

ello every one,
 
My first post on the forum and I am pretty new to networking.
 
I have a scenario where we have Meraki MX64 which already has IPSEC client VPN configured on it.
 
We bought fortigate 60E and now we want to configure SSL VPN port forwarding from meraki to this fortigate appliance.

We only have one Public IP address and its on meraki.

 

I have configured the local interface LAN 1 with local subnet IP address and can access the Fortigate.
 

At the moment this is what I have done.
 
Created a different vlan on meraki for Meraki port 2 as I was not able to assign it the same IP address as I have assigned to the LAN ports of fortigate.
 
Connected WAN1 of Fortigate to Meraki port 2 and assigned it an IP address from new VLAN 
 
Connected LAN1 of Fortigate to the local switch and assigned it an IP address from local subnet.
 
I can ping Fortigate WAN1 interface from Meraki.
 
Customize the SSL port on fortigate to 4443 and Created a port forward rule on meraki to WAN1 of fortigate on 4443.
 
It does not work, any thing which I am missing here.


Any other setting configurations I need to do to make it work.
 
Any help and assistance will be highly appreciated and looking forward to hear from the experts.
 
Thanks a lot..

4 Replies 4
PhilipDAth
Kind of a big deal
Kind of a big deal

Is the default route on the Fortigate pointing out its WAN interface to the MX?

Thanks Philip, I have not added any default route yet on fortigate, I will check for that.

 

 

What will be the statis route.

 

IP Address on WAN1 fortigate port is 192.168.90.253 this is connected to Port 2 on meraki, how would my static route look like ?? any help please..

PhilipDAth
Kind of a big deal
Kind of a big deal

It should point to whatever IP the MX has in that same subnet 192.168.90.something.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels