03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

OSPF over IPsec configuration Protecting OSPF with IPsec<br />

To configure OSPF area and interfaces - web-based manager<br />

1 On FortiGate_2, go to Router > Dynamic > OSPF.<br />

2 For Router ID, enter 10.0.0.2.<br />

Router ID 10.0.0.2<br />

Areas Select Create New, enter the Area and Type and then select OK.<br />

Area 0.0.0.0<br />

Type<br />

Interfaces<br />

Regular<br />

Name Enter a name for the OSPF interface, ospf_wan1 for example.<br />

Interface Select the virtual IPsec interface, tunnel_wan1<br />

IP 0.0.0.0<br />

3 For Networks, select Create New.<br />

4 Enter the following information for the loopback interface:<br />

IP/Netmask 10.0.0.2/255.255.255.255<br />

Area 0.0.0.0<br />

5 For Networks, select Create New.<br />

6 Enter the following information for the tunnel interface:<br />

IP/Netmask 10.1.1.0/255.255.255.0<br />

Area 0.0.0.0<br />

7 For Networks, select Create New.<br />

8 Enter the following information for the local LAN interface:<br />

IP/Netmask 10.31.101.0/255.255.255.0<br />

Area 0.0.0.0<br />

9 Select Apply.<br />

To configure OSPF area and interfaces - CLI<br />

If for example, your loopback interface is 10.0.0.2, your tunnel ends are on the<br />

10.1.1.0/24 network, your local LAN is 10.31.101.0/24, and your virtual IPsec interface is<br />

named tunnel_wan1, you would enter:<br />

config router ospf<br />

set router-id 10.0.0.2<br />

config area<br />

edit 0.0.0.0<br />

end<br />

config network<br />

edit 1<br />

set prefix 10.1.1.0 255.255.255.0<br />

next<br />

edit 2<br />

set prefix 10.31.101.0 255.255.255.0<br />

IPsec VPNs for FortiOS 4.0 MR3<br />

226 01-434-112804-20120111<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!