11.03.2015 Views

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

IPv6 <strong>IPSec</strong> <strong>VPN</strong>s<br />

Site-to-site IPv4 over IPv6 <strong>VPN</strong> example<br />

end<br />

next<br />

edit port3<br />

set 192.168.2.1/24<br />

end<br />

Configure <strong>FortiGate</strong> A <strong>IPSec</strong> settings<br />

The phase 1 configuration is the same as in the IPv6 over IPv6 example.<br />

config vpn ipsec phase1-interface<br />

edit toB<br />

set ip-version 6<br />

set interface port2<br />

set remote-gw6 fec0:0000:0000:0003:209:0fff:fe83:25c7<br />

set dpd enable<br />

set psksecret maryhadalittlelamb<br />

set proposal 3des-md5 3des-sha1<br />

end<br />

The phase 2 configuration is the same as you would use for an IPv4 <strong>VPN</strong>. By<br />

default, phase 2 selectors are set to accept all subnet addresses for source and<br />

destination.<br />

config vpn ipsec phase2-interface<br />

edit toB2<br />

set phase1name toB<br />

set proposal 3des-md5 3des-sha1<br />

set pfs enable<br />

set replay enable<br />

end<br />

Configure <strong>FortiGate</strong> A firewall policies<br />

Firewall policies are required to allow traffic between port3 and the IPsec interface<br />

toB in each direction. These are IPv4 firewall policies.<br />

config firewall policy<br />

edit 1<br />

set srcintf port3<br />

set dstintf toB<br />

set srcaddr all<br />

set dstaddr all<br />

set action accept<br />

set service ANY<br />

set schedule always<br />

next<br />

edit 2<br />

set srcintf toB<br />

set dstintf port3<br />

set srcaddr all<br />

set dstaddr all<br />

set action accept<br />

set service ANY<br />

set schedule always<br />

end<br />

<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />

01-30005-0065-20070716 121

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!