fortigate-ipsec-40-mr3
fortigate-ipsec-40-mr3
fortigate-ipsec-40-mr3
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Dynamic spokes configuration example Hub-and-spoke configurations<br />
2 Select OK.<br />
Configure the spokes<br />
Destination Address Name Select All.<br />
Action Select ACCEPT.<br />
NAT Enable.<br />
UTM Select the appropriate UTM profiles.<br />
In this example, all spokes have nearly identical configuration, requiring the following:<br />
phase 1 authentication parameters to initiate a connection with the hub<br />
phase 2 tunnel creation parameters to establish a VPN tunnel with the hub<br />
a source address that represents the network behind the spoke. This is the only part<br />
of the configuration that is different for each spoke.<br />
a destination address that represents the aggregate protected network<br />
a security policy to enable communications between the spoke and the aggregate<br />
protected network<br />
Define the IPsec configuration<br />
At each spoke, create the following configuration.<br />
To define the Phase 1 parameters<br />
1 At the spoke, go to VPN > IPsec > Auto Key (IKE).<br />
2 Select Create Phase 1, enter the following information, and select OK:<br />
Name Type a name, for example, toHub.<br />
Remote Gateway Static IP Address<br />
IP Address 172.16.10.1<br />
Local Interface Port2<br />
Mode Main<br />
Authentication Method Preshared Key<br />
Enter the preshared key. The value must be identical to the<br />
Pre-shared Key preshared key that you specified previously in the<br />
FortiGate_1 configuration.<br />
Peer Options Accept any peer ID<br />
Enable IPsec Interface<br />
Mode<br />
Select Advanced to see this option. Enable the option to<br />
create a route-based VPN.<br />
To define the Phase 2 parameters<br />
1 Go to VPN > IPsec > Auto Key (IKE).<br />
2 Select Create Phase 2, enter the following information, and select OK:<br />
Name Enter a name for the tunnel, for example, toHub_ph2.<br />
Phase 1<br />
Select the name of the phase 1 configuration that you defined<br />
previously, for example, toHub.<br />
Advanced Select to show the following Quick Mode Selector settings.<br />
IPsec VPNs for FortiOS 4.0 MR3<br />
98 01-434-112804-20120111<br />
http://docs.fortinet.com/