03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Redundant VPN configurations Partially-redundant route-based VPN example<br />

3 Select the WAN1 interface and select Edit. Enter the following information and then<br />

select OK:<br />

Addressing mode DHCP<br />

To configure the two IPsec interfaces (phase 1 configurations)<br />

1 Go to VPN > IPsec > Auto Key (IKE).<br />

2 Select Create Phase 1, enter the following information, and select OK:<br />

Name Site_2_A<br />

Remote Gateway Static IP Address<br />

IP Address 192.168.10.2<br />

Local Interface WAN1<br />

Mode Main<br />

Authentication Method Preshared Key<br />

Pre-shared Key Enter the preshared key.<br />

Peer Options<br />

Advanced<br />

Accept any peer ID<br />

Enable IPsec Interface Mode Select<br />

Dead Peer Detection Select<br />

3 Select Create Phase 1, enter the following information, and select OK:<br />

Name Site_2_B<br />

Remote Gateway Static IP Address<br />

IP Address 172.16.20.2<br />

Local Interface WAN1<br />

Mode Main<br />

Authentication Method Preshared Key<br />

Pre-shared Key Enter the preshared key.<br />

Peer Options<br />

Advanced<br />

Accept any peer ID<br />

Enable IPsec Interface Mode Select<br />

Dead Peer Detection Select<br />

To define the phase 2 configurations for the two VPNs<br />

1 Go to VPN > IPsec > Auto Key (IKE).<br />

2 Select Create Phase 2, enter the following information and select OK:<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 171<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!