03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FortiOS Handbook<br />

Protecting OSPF with IPsec<br />

Overview<br />

For enhanced security, OSPF dynamic routing can be carried over IPsec VPN links.<br />

The following topics are included in this section:<br />

Overview<br />

OSPF over IPsec configuration<br />

Creating a redundant configuration<br />

This chapter shows an example of OSPF routing conducted over an IPsec tunnel<br />

between two FortiGate units. The network shown in Figure 35 is a single OSPF area.<br />

FortiGate_1 is an Area border router that advertises a static route to 10.22.10.0/24 in<br />

OSPF. FortiGate_2 advertises its local LAN as an OSPF internal route.<br />

Figure 35: OSPF over an IPsec VPN tunnel<br />

Local LAN<br />

10.21.101.0/24<br />

10.22.10.0/24<br />

FortiGate_1<br />

Port 1<br />

Port 2<br />

172.20.120.141<br />

Port t 22<br />

192.168.0.131 311<br />

FortiGate_2 oort rtiG iGat ate_ e_2<br />

Port3 Port3<br />

10.1.1.1 VPN tunnel<br />

“tunnel_wan1”<br />

OSPF cost 10<br />

10.1.1.2<br />

10.1.2.1 VPN tunnel<br />

“tunnel_wan2”<br />

OSPF cost 200<br />

10.1.2.2<br />

Local LAN<br />

10.31.101.0/24<br />

The section “OSPF over IPsec configuration” describes the configuration with only one<br />

IPsec VPN tunnel, tunnel_wan1. Then, the section “Creating a redundant configuration”<br />

on page 227 describes how you can add a second tunnel to provide a redundant backup<br />

path. This is shown in Figure 35 as VPN tunnel “tunnel_wan2”.<br />

Only the parts of the configuration concerned with creating the IPsec tunnel and<br />

integrating it into the OSPF network are described. It is assumed that security policies are<br />

already in place to allow traffic to flow between the interfaces on each FortiGate unit.<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 221<br />

http://docs.fortinet.com/<br />

PPPPPPPPo PPort Port 11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!