03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IPsec VPN concepts VPN gateways<br />

Figure 2: VPN tunnel between two private networks<br />

Site A network<br />

10.10.1.0/24<br />

Site A A VPN V gateway<br />

(FortiGate FortiGate unit)<br />

IP a.1.2.3 IP b.4.5.6 4.5.6<br />

VPN tunnel<br />

Site B VPN gateway tew<br />

(FortiGate Gate unit unit)<br />

Site B network<br />

192.168.10.0/24<br />

Although the IPsec traffic may actually pass through many Internet routers, you can<br />

visualize the VPN tunnel as a simple secure connection between the two FortiGate units.<br />

Users on the two private networks do not need to be aware of the VPN tunnel. The<br />

applications on their computers generate packets with the appropriate source and<br />

destination addresses, as they normally do. The FortiGate units manage all the details of<br />

encrypting, encapsulating and sending the packets to the remote VPN gateway.<br />

The data is encapsulated in IPsec packets only in the VPN tunnel between the two VPN<br />

gateways. Between the user’s computer and the gateway, the data is on the secure<br />

private network and it is in regular IP packets.<br />

For example User1 on the Site A network, at IP address 10.10.1.7, sends packets with<br />

destination IP address 192.168.10.8, the address of User2 on the Site B network. The<br />

Site A FortiGate unit is configured to send packets with destinations on the 192.168.10.0<br />

network through the VPN, encrypted and encapsulated. Similarly, the Site B FortiGate<br />

unit is configured to send packets with destinations on the 10.10.1.0 network through the<br />

VPN tunnel to the Site A VPN gateway.<br />

In the site-to-site, or gateway-to-gateway VPN shown in Figure 2, the FortiGate units<br />

have static (fixed) IP addresses and either unit can initiate communication.<br />

You can also create a VPN tunnel between an individual PC running FortiClient and a<br />

FortiGate unit, as shown below. This is commonly referred to as Client-to-Gateway IPsec<br />

VPN.<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 15<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!