03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

GRE over IPsec (Cisco VPN) configurations Configuring the FortiGate unit<br />

To configure security policies - web-based manager<br />

1 Define an ACCEPT security policy to permit communications between the protected<br />

network and the GRE tunnel:<br />

Source Interface/Zone<br />

Select the interface that connects to the private network<br />

behind this FortiGate unit.<br />

Source Address Name All<br />

Destination<br />

Interface/Zone<br />

Select the GRE tunnel virtual interface you configured.<br />

Destination Address<br />

Name<br />

All<br />

Action ACCEPT<br />

NAT Disable<br />

2 To permit the remote client to initiate communication, you need to define a security<br />

policy for communication in that direction:<br />

Source Interface/Zone Select the GRE tunnel virtual interface you configured.<br />

Source Address Name All<br />

Destination<br />

Select the interface that connects to the private network<br />

Interface/Zone<br />

behind this FortiGate unit.<br />

Destination Address<br />

Name<br />

All<br />

Action ACCEPT.<br />

NAT Disable<br />

3 Define a pair of ACCEPT security policies to permit traffic to flow between the GRE<br />

virtual interface and the IPsec virtual interface:<br />

Source Interface/Zone<br />

Select the GRE virtual interface. See “Configuring the<br />

GRE tunnel” on page 214.<br />

Source Address Name All<br />

Destination<br />

Interface/Zone<br />

Destination Address<br />

Name<br />

Select the virtual IPsec interface you created. See<br />

“Configuring the IPsec VPN” on page 212.<br />

All<br />

Action ACCEPT.<br />

NAT Disable<br />

Source Interface/Zone<br />

Select the virtual IPsec interface you created. See<br />

“Configuring the IPsec VPN” on page 212.<br />

Source Address Name All<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 215<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!