03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Redundant VPN configurations Configure the VPN peers - route-based VPN<br />

Configure the VPN peers - route-based VPN<br />

VPN peers are configured using Interface Mode for redundant tunnels.<br />

Configure each VPN peer as follows:<br />

1 Ensure that the interfaces used in the VPN have static IP addresses.<br />

2 Create a phase 1 configuration for each of the paths between the peers. Enable IPsec<br />

Interface mode so that this creates a virtual IPsec interface. Enable dead peer<br />

detection so that one of the other paths is activated if this path fails.<br />

Enter these settings in particular:<br />

Path 1<br />

Remote Gateway Select Static IP Address.<br />

IP Address<br />

Type the IP address of the primary interface of the<br />

remote peer.<br />

Local Interface Select the primary public interface of this peer.<br />

Enable IPsec Interface Mode Enable<br />

Dead Peer Detection Enable<br />

Other settings as required by VPN.<br />

Path 2<br />

Remote Gateway Select Static IP Address.<br />

IP Address<br />

Type the IP address of the secondary interface of<br />

the remote peer.<br />

Local Interface Select the primary public interface of this peer.<br />

Enable IPsec Interface Mode Enable<br />

Dead Peer Detection Enable<br />

Other settings as required by VPN.<br />

Path 3<br />

Remote Gateway Select Static IP Address.<br />

IP Address<br />

Type the IP address of the primary interface of the<br />

remote peer.<br />

Local Interface Select the secondary public interface of this peer.<br />

Enable IPsec Interface Mode Enable<br />

Dead Peer Detection Enable<br />

Other settings as required by VPN.<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 153<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!