03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Redundant VPN configurations Redundant route-based VPN configuration example<br />

9 Select Create New, enter the following information, and select OK:<br />

Configuring FortiGate_2<br />

Service Any<br />

Action ACCEPT<br />

Source Interface/Zone Site_1_D<br />

Source Address Name All<br />

Destination Interface/Zone Internal<br />

Destination Address Name All<br />

Schedule Always<br />

Service Any<br />

Action ACCEPT<br />

The configuration for FortiGate_2 is very similar that of FortiGate_1. You must<br />

configure the interfaces involved in the VPN<br />

define the phase 1 configuration for each of the four possible paths, creating a virtual<br />

IPsec interface for each one<br />

define the phase 2 configuration for each of the four possible paths<br />

configure routes for the four IPsec interfaces, assigning the appropriate priorities<br />

configure incoming and outgoing security policies between the internal interface and<br />

each of the virtual IPsec interfaces<br />

To configure the network interfaces<br />

1 Go to System > Network > Interface.<br />

2 Select the Internal interface and then select Edit. Enter the following information and<br />

then select OK:<br />

Addressing mode Manual<br />

IP/Netmask 10.31.101.0/255.255.255.0<br />

3 Select the WAN1 interface and then select Edit. Enter the following information and<br />

then select OK:<br />

Addressing mode Manual<br />

IP/Netmask 192.168.20.2/255.255.255.0<br />

4 Select the WAN2 interface and then select Edit. Enter the following information and<br />

then select OK:<br />

Addressing mode Manual<br />

IP/Netmask 172.16.30.2/255.255.255.0<br />

To configure the IPsec interfaces (phase 1 configurations)<br />

1 Go to VPN > IPsec > Auto Key (IKE).<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 161<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!