FortiGate IPSec VPN User Guide - FirewallShop.com
FortiGate IPSec VPN User Guide - FirewallShop.com
FortiGate IPSec VPN User Guide - FirewallShop.com
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
IPv6 <strong>IPSec</strong> <strong>VPN</strong>s<br />
Site-to-site IPv4 over IPv6 <strong>VPN</strong> example<br />
end<br />
next<br />
edit port3<br />
set 192.168.2.1/24<br />
end<br />
Configure <strong>FortiGate</strong> A <strong>IPSec</strong> settings<br />
The phase 1 configuration is the same as in the IPv6 over IPv6 example.<br />
config vpn ipsec phase1-interface<br />
edit toB<br />
set ip-version 6<br />
set interface port2<br />
set remote-gw6 fec0:0000:0000:0003:209:0fff:fe83:25c7<br />
set dpd enable<br />
set psksecret maryhadalittlelamb<br />
set proposal 3des-md5 3des-sha1<br />
end<br />
The phase 2 configuration is the same as you would use for an IPv4 <strong>VPN</strong>. By<br />
default, phase 2 selectors are set to accept all subnet addresses for source and<br />
destination.<br />
config vpn ipsec phase2-interface<br />
edit toB2<br />
set phase1name toB<br />
set proposal 3des-md5 3des-sha1<br />
set pfs enable<br />
set replay enable<br />
end<br />
Configure <strong>FortiGate</strong> A firewall policies<br />
Firewall policies are required to allow traffic between port3 and the IPsec interface<br />
toB in each direction. These are IPv4 firewall policies.<br />
config firewall policy<br />
edit 1<br />
set srcintf port3<br />
set dstintf toB<br />
set srcaddr all<br />
set dstaddr all<br />
set action accept<br />
set service ANY<br />
set schedule always<br />
next<br />
edit 2<br />
set srcintf toB<br />
set dstintf port3<br />
set srcaddr all<br />
set dstaddr all<br />
set action accept<br />
set service ANY<br />
set schedule always<br />
end<br />
<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />
01-30005-0065-20070716 121