03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FortiOS Handbook<br />

Hub-and-spoke configurations<br />

This section describes how to set up hub-and-spoke IPsec VPNs. The following topics<br />

are included in this section:<br />

Configuration overview<br />

Configure the hub<br />

Configure the spokes<br />

Configuration overview<br />

Dynamic spokes configuration example<br />

In a hub-and-spoke configuration, VPN connections radiate from a central FortiGate unit<br />

(the hub) to a number of remote peers (the spokes). Traffic can pass between private<br />

networks behind the hub and private networks behind the remote peers. Traffic can also<br />

pass between remote peer private networks through the hub.<br />

Figure 10: Example hub-and-spoke configuration<br />

HR network<br />

Site_1<br />

Hub Hub<br />

Finance network<br />

The actual implementation varies in complexity depending on<br />

whether the spokes are statically or dynamically addressed<br />

the addressing scheme of the protected subnets<br />

how peers are authenticated<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 85<br />

http://docs.fortinet.com/<br />

Spoke_1 poke_1<br />

Spoke_2 Spok<br />

Site_2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!