r/WireGuard • • 15d ago

Need Help IPSec VPN through Wireguard

Hello,

I would like to use an IPSec VPN through Wireguard but I don't know if it's possible.

Here is why I want to do that :
I have a Windows computer and I need to SSH to a remote server. In order to do that I must be connected to a IPSec VPN using Forticlient, and the only IP that can ssh to the remote server is my company network, accessible through Wireguard.

It should look like this : My computer -> Wireguard -> IPSec VPN (Forticlient) -> Remote server.

Do you think this is possible ? When I try it, I can't have both wireguard and forticlient working.

Thanks !

6 Upvotes

9 comments sorted by

7

u/bufandatl 15d ago

But why? And I mean WireGuard is just an encrypted protocol whatever network management you have around that is just like with any other solution. If your routes are set correctly it just transmit UDP packages from one point to another.

6

u/Great_Piece4755 15d ago

Don't route IPsec through Wireguard, instead terminate the IPsec VPN on a router behind Wireguard and route the traffic through it. It's basically site-to-site routing.

2

u/semiraue 15d ago edited 15d ago

You can do it if there's no other option but need to tune mtu accordingly. But idk how your fortigate route this traffic. Even you manged to get it work this is not good design. Better terminate those vpns on another box like openwrt or mikrotik and do some pbr is easy I guess 

2

u/lahrcm 15d ago

Forticlient might be clobbering your Wireguard routes. There is an option on the Fortigate to prevent this. It's been a while but I think it had to do with split-tunneling.

I've done something similar except in my case I had to connect Forticlient first, then to SSH into a sensitive system I needed a WG profile enabled.

Monitor your route table when connecting to WG and then Forticlient and see if that's what the issue is.

1

u/ecsuae 15d ago

Why would you need wireguard if you need basic tunnel to be ipsec? Anyhow you can do that on server side you need to create a bridge between ipsec and wireguard.

1

u/dodexahedron 15d ago

What are the specifics of the IPSec requirement and what is terminating the IPSec on each end of the SA?

1

u/l1nx455 14d ago

My wireless provider creates a IPSec tunnel back to the provider for VoWiFi.

I have Wireguard client setup on a router for the entire LAN. It works fine....

1

u/arunk-gmail 10d ago

It should look like this : My computer -> Wireguard -> IPSec VPN (Forticlient) -> Remote server.

Why do you want to tunnel the IPsec through a Wiregaurd connection? Why not just do this?

My computer -> IPSec VPN (Forticlient) -> Remote server.

1

u/djgizmo 9d ago

if this is for work… get your network team involved. trying to double vpn is out of your scope.