Tulsa Finance

Aug 27 2017

Site-to-site IPsec VPN with two FortiGates – Fortinet Cookbook #hub-and-spoke #vpn


#

Site-to-site IPsec VPN with two FortiGates

Share this post:

In this example, you will allow transparent communication between two networks that are located behind different FortiGates at different offices using route-based IPsec VPN. The VPN will be created on both FortiGates by using the VPN Wizard s Site to Site FortiGate template.

In this example, one office will be referred to as HQ and the other will be referred to as Branch.

1. Configuring the HQ IPsec VPN

On the HQ FortiGate, go to VPN IPsec Wizard and select Site to Site FortiGate .

In the Authentication step, set the Branch FortiGate s IP as the Remote Gateway (in the example, 172.20.120.142 ). After you enter the gateway, an available interface will be assigned as the Outgoing Interface. If you wish to use a different interface, select Change .

In the Policy Routing section, set Local Interface to your lan interface. The Local Subnet will be added automatically. Set Remote Subnets to the Branch FortiGate s local subnet (in the example, 192.168.50.0/24 ).

A summary page shows the configuration created by the wizard, including firewall addresses, firewall address groups, a static route. and security policies.

2. Configuring the Branch IPsec VPN

On the Branch FortiGate, go to VPN IPsec Wizard and select Site to Site FortiGate .

In the Authentication step, set the HQ FortiGate s IP as the Remote Gateway (in the example, 172.20.120.123 ). After you enter the gateway, an available interface will be assigned as the Outgoing Interface. If you wish to use a different interface, select Change .

Set the same Pre-shared Key that was used for HQ s VPN.

In the Policy Routing section, set Local Interface to your lan interface. The Local Subnet will be added automatically. Set Remote Subnets to the HQ FortiGate s local subnet (in the example, 192.168.100.0/24 ).

A summary page shows the configuration created by the wizard, including firewall addresses, firewall address groups, a static route, and security policies.

3. Results

A user on either of the office networks should be able to connect to any address on the other office network transparently.

If you need to generate traffic to test the connection, ping the Branch FortiGate s internal interface from the HQ s internal network.

Go to VPN Monitor IPsec Monitor to verify the status of the VPN tunnel. Ensure that its Status is Up and that traffic is flowing.

Download

Technical Writer & Head Cookbook Chef at Fortinet

Victoria Martin works in Ottawa as part of the FortiOS technical documentation team. She graduated with a Bachelor’s degree from Mount Allison University, after which she attended Humber College’s book publishing program, followed by the more practical technical writing program at Algonquin College. She does need glasses but also likes wearing them, since glasses make you look smarter.

Latest posts by Victoria Martin (see all )

Is there any benefit to using the fortigate template vs custom templates between two fortigates? Is it just ease of deployment ?

I am having trouble setting up a site-to-site IPsec VPN between a Checkpoint and a Fortinet Fortigate 110C. The challenge is on the Fortigate 110C end. Is there any help resources you can refer me to?
Thanks

I found one resource in the Knowledge Base that talks about setting up a VPN between a FortiGate and a Checkpoint NGX appliance. It s quite old but it might be still be useful in helping you figure out network settings. You can find it at http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC docType=kc externalId=12091 sliceId=1 docTypeID=DT_KCARTICLE_1_1 dialogID=102601047 stateId=0%200%20102599339

Otherwise, I d suggest contacting Fortinet Support.

Can create redundant tunnel if we have two different ISP connections?

Hi, I m having trouble pinging from HQ to Branch Office on VPN IPSEC DialUp tunnel. Why is happening this? I can ping from the Branch to the HQ but no HQ to Branch. I have traffic up/down on the VPN.

Thank you for your help!

P.S. HQ Fortigate is 300B last update and Branch Fortigate is 60B 4.0 MR3 Patch 18

sounds like a firewall policy issue

Hi sir. I m new in firewall. I have 2 fortinet 30E configuring site to site VPN using a broadband wireless connection does it work? What IP i will set in the remote gateway? The broadband giving me a dhcp address for interface w/c is private ip. Thank you all.

In order to configure a site-to-site IPsec, the FortiGates will need to be able to connect to each other using public IPs. It sounds like you need to contact your ISP in order to get this set up.

what if i have multiple remote subnets. How will i add them?

Hi Marzooq, for each subnet you would need a different phase2. Each phase2 is bound to a single/global phase1. Here s some example CLI: http://kb.fortinet.com/kb/documentLink.do?externalID=FD33873

Hi there, How can i create a site to site vpn using CLI? Do you have predefined examples that you can send me?

Hi Bibek, here s some example CLI for phase1 and phase2 IPsec configuration (on one endpoint; the other endpoint confniguration would be quite similar, with source and destination subnets reversed, most likely):

config vpn ipsec phase1-interface
edit
set interface wan1
set peertype any
set dpd on-idle
set wizard-type static-fortigate
set remote-gw
set psksecret ENC [hash]
set dpd-retryinterval 5
next
end
config vpn ipsec phase2-interface
edit
set phase1name
set src-subnet 192.168.1.0 255.255.255.0
set dst-subnet 192.169.1.0 255.255.255.0
next
end

You then add your policies as required.



Written by admin


7 responses to “Site-to-site IPsec VPN with two FortiGates – Fortinet Cookbook #hub-and-spoke #vpn

  • Odstawianie sterydow przeciek z Miedzyborowa 11/29/2010 1EMULATION Video Game Review Master List
    Rule 14 3 and null macros Estate sale #3
    about ARMSCOR 22 Mag ammo Kui loll ma olen
    Советник Bargain 2 0 Marlin Model 90 Steel Shot
    13 июля 2014 US Para tijdens 11 november herdenking Ieper 11 11 14

  • i will try to show off my SVO business internet san diego Werbeintro kostenlos erhaltlich
    fiber/yarn/handspun for sale masters program in education Too many forums
    Problem with Felicity 2 florida treatment centers Poison Kandy Coffee Morning Palmview February 25 2018
    Tutorial lazy load all products lists and boost performance classes i need to take to become a nurse Collezione modellini auto in scala Automodellismo statico
    Re Bantam egg size uvu online classes set memory limit temp

  • AROS C environment help needed with linking apache derby vs mysql spi 12 30×6 70 Mayor 11 80×310 calcetin 11 60
    Why is it so hard to find an Auto Painting Shop vip voice Launch of our online aquatic plant store www sreepadma com
    Free agent watch online bachelor\’s degree Valentines Gifts / Gift Ideas
    Si vous aviez l’erreur 406 sur votre ecran c’est regle st louis tax attorney 1 Januar 2013
    A unique situation with a unique Weapon how to copy a table in sql Is er draagvlak voor een MTB nl URBAN bikersdag Ja dus

  • New York Susquehanna Western cheap auto insurance tx VENDUS 2 cables secteur Oyaide Tunami GPX e
    Mr Smith Smith Sessions 096 15 03 2018 johnson county ambulance Stopover van 3 nachten waar slapen
    Sub forum Nutrition car insurance in new york Podesavanje rada karburatora i prijenosa
    Thought it was a front wheel bearing usc mha program Morserzugwagen M 17
    Создание команды проекта mba project management online Toy Fair 2018 Virtual Augmented Reality Session

  • Kernel 2 6 7 linode3 1um game dev map ATI TV Wonder Combo PCI Express Card Review
    Receta de Mouse de Chocolate sin Lactosa online schools for moms Ansetzen Hals zu
    RUTTU VAJA ABI RUTTU praxis ehr miks ta nii teeb
    Valoraciones Lakers 2016 2017 medical billing duties Any info yet on the 3 3 engine internals
    “I Anteil des PI Reglers “”RLT30_FB_CTRL_PI”” hangt sich auf ” woodstock ga personal injury attorney Porky the tank

  • Lef side block doesnt appear on only sub category garage door repair thornton Wrong summary chart
    February 27 2008 microsoft exchange replacement MBL League PB ini File looking for an expert to take look
    WHDload slave tutorial online non profit colleges Itunes playlist problem
    Super Football 2600 7800 End Label human resources certifications available It Shouldnt have to cost 600000 to ensure speakers can speak freely
    OBAMA REQUESTS 1 1 BILLION DOJ 382 1 MILLION FOR GUN CONTROL hodgkin lymphoma causes UnibootX Clover nie bootuje

  • How do I recover from deleting an allowed file extension Unorthodox/Lazy Playoff Seeding / Format in SCHSL Basketball
    Asus H110M A i OS X FITOTERAPIA BORELIOZY biorezonans
    Coyote Fox Swap Engine Harness Problema con UPL y dispositivos USB Solucionado
    7/04/2017 11 42pm Belegung Baustein TIMER_1 in PCWORX
    Day of the Week Used Klim Tek Vest For Sale SOLD

  • Leave a Reply

    Your email address will not be published. Required fields are marked *