FortiGate IPSec VPN User Guide - FirewallShop.com
FortiGate IPSec VPN User Guide - FirewallShop.com
FortiGate IPSec VPN User Guide - FirewallShop.com
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Configuration overview<br />
Gateway-to-gateway configurations<br />
You can set up a fully meshed or partially meshed configuration (see Figure 2 and<br />
Figure 3).<br />
Figure 2:<br />
Fully meshed configuration<br />
Fully meshed<br />
<strong>FortiGate</strong>_2<br />
<strong>FortiGate</strong>_3<br />
<strong>FortiGate</strong>_1<br />
<strong>FortiGate</strong>_4<br />
<strong>FortiGate</strong>_5<br />
In a fully meshed network, all <strong>VPN</strong> peers are connected to each other, with one<br />
hop between peers. This topology is the most fault-tolerant: if one peer goes<br />
down, the rest of the network is not affected. This topology is difficult to scale<br />
because it requires connections between all peers. In addition, unnecessary<br />
<strong>com</strong>munication can occur between peers. We re<strong>com</strong>mend a hub-and-spoke<br />
configuration instead (see “Hub-and-spoke configurations” on page 33).<br />
Figure 3:<br />
Partially meshed configuration<br />
Paritally meshed<br />
<strong>FortiGate</strong>_2<br />
<strong>FortiGate</strong>_3<br />
<strong>FortiGate</strong>_1<br />
<strong>FortiGate</strong>_4<br />
<strong>FortiGate</strong>_5<br />
A partially meshed network is similar to a fully meshed network, but instead of<br />
having tunnels between all peers, tunnels are only configured between peers that<br />
<strong>com</strong>municate with each other regularly.<br />
Gateway-to-gateway infrastructure requirements<br />
• The <strong>FortiGate</strong> units at both ends of the tunnel must be operating in NAT/Route<br />
mode and have static public IP addresses.<br />
<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />
20 01-30005-0065-20070716