03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Partially-redundant route-based VPN example Redundant VPN configurations<br />

Configuring FortiGate_1<br />

You must<br />

configure the interfaces involved in the VPN<br />

define the phase 1 configuration for each of the two possible paths, creating a virtual<br />

IPsec interface for each one<br />

define the phase 2 configuration for each of the two possible paths<br />

configure incoming and outgoing security policies between the internal interface and<br />

each of the virtual IPsec interfaces<br />

To configure the network interfaces<br />

1 Go to System > Network > Interface.<br />

2 Select the Internal interface and select Edit. Enter the following information and then<br />

select OK:<br />

Addressing mode Manual<br />

IP/Netmask 10.21.101.2/255.255.255.0<br />

3 Select the WAN1 interface and select Edit. Enter the following information and then<br />

select OK:<br />

Addressing mode Manual<br />

IP/Netmask 192.168.10.2/255.255.255.0<br />

4 Select the WAN2 interface and select Edit. Enter the following information and then<br />

select OK:<br />

Addressing mode Manual<br />

IP/Netmask 172.16.20.2/255.255.255.0<br />

To configure the IPsec interfaces (phase 1 configurations)<br />

1 Go to VPN > IPsec > Auto Key (IKE).<br />

2 Select Create Phase 1, enter the following information, and select OK:<br />

Name Site_1_A<br />

Remote Gateway Dialup User<br />

Local Interface WAN1<br />

Mode Main<br />

Authentication Method Preshared Key<br />

Pre-shared Key Enter the preshared key.<br />

Peer Options<br />

Advanced<br />

Accept any peer ID<br />

IPsec VPNs for FortiOS 4.0 MR3<br />

168 01-434-112804-20120111<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!