VPN IPSEC behind NAT (one side)

aringad

Prominent
Jun 8, 2017
2
0
510
Hello to everybody. I have two offices connected to the internet. One has a Fortigate that is the public ip on the wan side. In the second one, the public ip is managed by ISP router, that can do NAT and I will install a Mikrotik routerboard behind.
I would like to create an IPSEC tunnel behind the two offices using Fortigate and Mikrotik. Is it a problem the NAT? I mean, I will NAT UDP ports that are required, but am I missing something? Like outbound nat or similar?
Thanks in advance

Giuliano
 

aringad

Prominent
Jun 8, 2017
2
0
510
little specification: I will nat 500 and 4500 UDP port. I don't if this is sufficient. Dunno much about ESP and the router I have that will do NAT is a technicolor with a very poor firmware.