03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring the FortiGate unit GRE over IPsec (Cisco VPN) configurations<br />

Destination<br />

Interface/Zone<br />

Destination Address<br />

Name<br />

Select the GRE virtual interface. See “Configuring the<br />

GRE tunnel” on page 214.<br />

All<br />

Action Select ACCEPT.<br />

NAT Disable.<br />

To configure security policies - CLI<br />

config firewall policy<br />

edit 1 // LAN to GRE tunnel<br />

set srcintf port2<br />

set dstintf gre1<br />

set srcaddr all<br />

set dstaddr all<br />

set action accept<br />

set schedule always<br />

set service ANY<br />

next<br />

edit 2 // GRE tunnel to LAN<br />

set srcintf gre1<br />

set dstintf port2<br />

set srcaddr all<br />

set dstaddr all<br />

set action accept<br />

set schedule always<br />

set service ANY<br />

next<br />

edit 3 // GRE tunnel to IPsec interface<br />

set srcintf "gre1"<br />

set dstintf "tocisco"<br />

set srcaddr "all"<br />

set dstaddr "all"<br />

set action accept<br />

set schedule "always"<br />

set service "ANY"<br />

next<br />

edit 4 // IPsec interface to GRE tunnel<br />

set srcintf "tocisco"<br />

set dstintf "gre1"<br />

set srcaddr "all"<br />

set dstaddr "all"<br />

set action accept<br />

set schedule "always"<br />

set service "ANY"<br />

end<br />

IPsec VPNs for FortiOS 4.0 MR3<br />

216 01-434-112804-20120111<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!