#Configuration Guide# VPN IPSEC between Sites with Overlapping Subnets
  

FGentili Lv1Posted Mar-28-2025 18:29


Problem

Create an IPSEC Tunnel between two site  with overlapping subnet.
On Site A  : Sangfor NGSF firewall
On Site B: Thirty Party firewall

Network Layout



Workstation on Site A can't  connect  to Workstation/Server on SIte B without changing its own address ( and the reverse)

Here the Solution

First of all choose two subnets, one for each site that are not overlapping so:

Site A
Subnet 192.168.0.0/24 will be translated to10.251.16.0/24

Site B
Subnet 192.168.0.0/24 will be translated to 192.168.4.0/24

Let's go :

1. Object definition

First of all define object on Sangfor Firewall :


2. Setup NAT RULES

You need to create two NAT rules :
- SNAT rules to change source address for traffic flowing from Site A to SiteB
- DNAT rules to change destination address flowing from Site B to Site A

2.1 Outgoing Traffic Form Site A to Site B ( SNAT Rules )


in such way 192.168.0.1 will be translated in 10.251.16.1, 192.168.0.2 will be translated in 10.251.16.2 and so on .. last address byte is not translated


2.2 Incoming Traffic Form Site B to Site A ( DNAT Rules )



Pay attention to use: IP ADDRESS PREFIX, in such way only subnet portion will be translated

10.251.16.1 will be translated in 192.168.0.1
10.251.16.2 will be translated in 192.168.0.2

3. Access control


You need to create rules to permit traffic between subnet using REAL IP ADDRESS

Site A to Site B:


Site B to Site A:


4. Setup VPN IPSEC
VPN configruation  follow same step as described in : https://community.sangfor.com/fo ... ead&tid=7455&page=1


on phase 2 configuration you need to specify translated address on encrypted traffic.

Hope it helps some headache ...

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x

Like this topic? Like it or reward the author.

Creating a topic earns you 5 coins. A featured or excellent topic earns you more coins. What is Coin?

Enter your mobile phone number and company name for better service. Go

fuadmahbubun Lv2Posted Apr-07-2025 14:22
  
Thank you for sharing
Newbie517762 Lv5Posted Mar-31-2025 09:13
  
Thank you for sharing your valuable contributions.
Newbie617866 Posted Mar-31-2025 02:50
  
Thanks for sharing
Kbob Lv2Posted Mar-30-2025 12:40
  
I was wondering if there are any additional risks to be aware of when using NAT in this VPN?
Rendy Rinaldy Lv2Posted Mar-30-2025 06:46
  
Will this NAT method affect the performance or latency of inter-site connections?
Ayra Posted Mar-29-2025 17:18
  
Thanks for sharing
AR Lv2Posted Mar-29-2025 02:03
  
Thanks for sharing
Enrico Vanzetto Lv4Posted Mar-28-2025 19:33
  
Hi, very useful. Thanks