11.03.2015 Views

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Site-to-site IPv4 over IPv6 <strong>VPN</strong> example<br />

IPv6 <strong>IPSec</strong> <strong>VPN</strong>s<br />

config firewall policy6<br />

edit 1<br />

set srcintf port3<br />

set dstintf toA<br />

set srcaddr all6<br />

set dstaddr all6<br />

set action accept<br />

set service ANY<br />

set schedule always<br />

next<br />

edit 2<br />

set srcintf toA<br />

set dstintf port3<br />

set srcaddr all6<br />

set dstaddr all6<br />

set action accept<br />

set service ANY<br />

set schedule always<br />

end<br />

config router static6<br />

edit 1<br />

set device port2<br />

set dst 0::/0<br />

next<br />

edit 2<br />

set device toA<br />

set dst fec0:0000:0000:0000::/64<br />

end<br />

Site-to-site IPv4 over IPv6 <strong>VPN</strong> example<br />

In this example, two private networks with IPv4 addressing <strong>com</strong>municate securely<br />

over IPv6 infrastructure.<br />

Figure 25: Example IPv4-over-IPv6 <strong>VPN</strong> topology<br />

<strong>FortiGate</strong> A<br />

<strong>FortiGate</strong> B<br />

Port3<br />

Port 2<br />

feco:0001:209:0fff:fe83:25f2<br />

Internet<br />

Port3<br />

Port 2<br />

feco:0001:209:0fff:fe83:25C7<br />

192.168.2.0/24<br />

192.168.3.0/24<br />

Configure <strong>FortiGate</strong> A interfaces<br />

Port 2 connects to the IPv6 public network and port 3 connects to the IPv4 LAN.<br />

config system interface<br />

edit port2<br />

config ipv6<br />

set ip6-address fec0::0001:209:0fff:fe83:25f2/64<br />

<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />

120 01-30005-0065-20070716

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!