03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Dynamic spokes configuration example Hub-and-spoke configurations<br />

2 Select OK.<br />

Configure the spokes<br />

Destination Address Name Select All.<br />

Action Select ACCEPT.<br />

NAT Enable.<br />

UTM Select the appropriate UTM profiles.<br />

In this example, all spokes have nearly identical configuration, requiring the following:<br />

phase 1 authentication parameters to initiate a connection with the hub<br />

phase 2 tunnel creation parameters to establish a VPN tunnel with the hub<br />

a source address that represents the network behind the spoke. This is the only part<br />

of the configuration that is different for each spoke.<br />

a destination address that represents the aggregate protected network<br />

a security policy to enable communications between the spoke and the aggregate<br />

protected network<br />

Define the IPsec configuration<br />

At each spoke, create the following configuration.<br />

To define the Phase 1 parameters<br />

1 At the spoke, go to VPN > IPsec > Auto Key (IKE).<br />

2 Select Create Phase 1, enter the following information, and select OK:<br />

Name Type a name, for example, toHub.<br />

Remote Gateway Static IP Address<br />

IP Address 172.16.10.1<br />

Local Interface Port2<br />

Mode Main<br />

Authentication Method Preshared Key<br />

Enter the preshared key. The value must be identical to the<br />

Pre-shared Key preshared key that you specified previously in the<br />

FortiGate_1 configuration.<br />

Peer Options Accept any peer ID<br />

Enable IPsec Interface<br />

Mode<br />

Select Advanced to see this option. Enable the option to<br />

create a route-based VPN.<br />

To define the Phase 2 parameters<br />

1 Go to VPN > IPsec > Auto Key (IKE).<br />

2 Select Create Phase 2, enter the following information, and select OK:<br />

Name Enter a name for the tunnel, for example, toHub_ph2.<br />

Phase 1<br />

Select the name of the phase 1 configuration that you defined<br />

previously, for example, toHub.<br />

Advanced Select to show the following Quick Mode Selector settings.<br />

IPsec VPNs for FortiOS 4.0 MR3<br />

98 01-434-112804-20120111<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!