03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Contents<br />

Protecting OSPF with IPsec 221<br />

Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 221<br />

OSPF over IPsec configuration. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222<br />

Configuring the IPsec VPN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222<br />

Configuring static routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223<br />

Configuring OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223<br />

FortiGate_1 OSPF configuration . . . . . . . . . . . . . . . . . . . . . . . . 223<br />

FortiGate_2 OSPF configuration . . . . . . . . . . . . . . . . . . . . . . . . 225<br />

Creating a redundant configuration . . . . . . . . . . . . . . . . . . . . . . . . . . 227<br />

Adding the second IPsec tunnel . . . . . . . . . . . . . . . . . . . . . . . . . . 227<br />

Adding the OSPF interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 227<br />

Hardware offloading and acceleration 229<br />

Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229<br />

IPsec session offloading requirements. . . . . . . . . . . . . . . . . . . . . . . 229<br />

Packet offloading requirements . . . . . . . . . . . . . . . . . . . . . . . . . . 230<br />

IPsec encryption offloading . . . . . . . . . . . . . . . . . . . . . . . . . . . . 230<br />

HMAC check offloading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 230<br />

IPsec offloading configuration examples. . . . . . . . . . . . . . . . . . . . . . . . 231<br />

Accelerated route-based VPN configuration. . . . . . . . . . . . . . . . . . . . 231<br />

Accelerated policy-based VPN configuration . . . . . . . . . . . . . . . . . . . 233<br />

Monitoring and troubleshooting 235<br />

Monitoring VPN connections . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235<br />

Monitoring connections to remote peers . . . . . . . . . . . . . . . . . . . . . 235<br />

Monitoring dialup IPsec connections . . . . . . . . . . . . . . . . . . . . . . . 235<br />

Testing VPN connections. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 236<br />

Testing VPN connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 236<br />

LAN interface connection . . . . . . . . . . . . . . . . . . . . . . . . . . . 237<br />

Dialup connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237<br />

Troubleshooting VPN connections. . . . . . . . . . . . . . . . . . . . . . . . . 237<br />

Logging VPN events . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 239<br />

VPN troubleshooting tips . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 241<br />

The VPN proposal is not connecting . . . . . . . . . . . . . . . . . . . . . 241<br />

General troubleshooting tips . . . . . . . . . . . . . . . . . . . . . . . . . . . . 241<br />

A word about NAT devices. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 242<br />

Index 243<br />

IPsec VPNs for FortiOS 4.0 MR3<br />

10 01-434-112804-20120111<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!