11.03.2015 Views

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Site-to-site IPv6 over IPv4 <strong>VPN</strong> example<br />

IPv6 <strong>IPSec</strong> <strong>VPN</strong>s<br />

Site-to-site IPv6 over IPv4 <strong>VPN</strong> example<br />

In this example, IPv6-addressed private networks <strong>com</strong>municate securely over<br />

IPv4 public infrastructure.<br />

Figure 26: Example IPv6-over-IPv4 <strong>VPN</strong> topology<br />

<strong>FortiGate</strong> A<br />

<strong>FortiGate</strong> B<br />

Internet<br />

Port3<br />

Port 2<br />

10.0.0.1/24<br />

Port 2<br />

10.0.1.1/24<br />

Port3<br />

fec0:0000:0000:0000::/64<br />

fec0:0000:0000:0004::/64<br />

Configure <strong>FortiGate</strong> A interfaces<br />

Port 2 connects to the IPv4 public network and port 3 connects to the IPv6 LAN.<br />

config system interface<br />

edit port2<br />

set 10.0.0.1/24<br />

next<br />

edit port3<br />

config ipv6<br />

set ip6-address fec0::0001:209:0fff:fe83:25f3/64<br />

end<br />

Configure <strong>FortiGate</strong> A <strong>IPSec</strong> settings<br />

The phase 1 configuration uses IPv4 addressing.<br />

config vpn ipsec phase1-interface<br />

edit toB<br />

set interface port2<br />

set remote-gw 10.0.1.1<br />

set dpd enable<br />

set psksecret maryhadalittlelamb<br />

set proposal 3des-md5 3des-sha1<br />

end<br />

The phase 2 configuration uses IPv6 selectors. By default, phase 2 selectors are<br />

set to accept all subnet addresses for source and destination. The default setting<br />

for src-addr-type and dst-addr-type is subnet. The IPv6 equivalent is<br />

subnet6. The default subnet addresses are 0.0.0.0/0 for IPv4, ::/0 for IPv6.<br />

config vpn ipsec phase2-interface<br />

edit toB2<br />

set phase1name toB<br />

set proposal 3des-md5 3des-sha1<br />

set pfs enable<br />

set replay enable<br />

set src-addr-type subnet6<br />

set dst-addr-type subnet6<br />

end<br />

<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />

124 01-30005-0065-20070716

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!