11.03.2015 Views

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuration overview<br />

Gateway-to-gateway configurations<br />

You can set up a fully meshed or partially meshed configuration (see Figure 2 and<br />

Figure 3).<br />

Figure 2:<br />

Fully meshed configuration<br />

Fully meshed<br />

<strong>FortiGate</strong>_2<br />

<strong>FortiGate</strong>_3<br />

<strong>FortiGate</strong>_1<br />

<strong>FortiGate</strong>_4<br />

<strong>FortiGate</strong>_5<br />

In a fully meshed network, all <strong>VPN</strong> peers are connected to each other, with one<br />

hop between peers. This topology is the most fault-tolerant: if one peer goes<br />

down, the rest of the network is not affected. This topology is difficult to scale<br />

because it requires connections between all peers. In addition, unnecessary<br />

<strong>com</strong>munication can occur between peers. We re<strong>com</strong>mend a hub-and-spoke<br />

configuration instead (see “Hub-and-spoke configurations” on page 33).<br />

Figure 3:<br />

Partially meshed configuration<br />

Paritally meshed<br />

<strong>FortiGate</strong>_2<br />

<strong>FortiGate</strong>_3<br />

<strong>FortiGate</strong>_1<br />

<strong>FortiGate</strong>_4<br />

<strong>FortiGate</strong>_5<br />

A partially meshed network is similar to a fully meshed network, but instead of<br />

having tunnels between all peers, tunnels are only configured between peers that<br />

<strong>com</strong>municate with each other regularly.<br />

Gateway-to-gateway infrastructure requirements<br />

• The <strong>FortiGate</strong> units at both ends of the tunnel must be operating in NAT/Route<br />

mode and have static public IP addresses.<br />

<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />

20 01-30005-0065-20070716

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!