11.03.2015 Views

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Dynamic spokes configuration example<br />

Hub-and-spoke configurations<br />

Action<br />

NAT<br />

Select ACCEPT<br />

Enable<br />

Source Interface/Zone Select the spoke’s interface to the internal (private) network.<br />

Source Address Name Select this spoke’s address name.<br />

Destination Interface/Zone Select the virtual <strong>IPSec</strong> interface you created.<br />

Destination Address Name Select the spoke address group you defined in Step 1.<br />

Action<br />

NAT<br />

Select ACCEPT<br />

Enable<br />

3 Place this policy or policies in the policy list above any other policies having similar<br />

source and destination addresses.<br />

Dynamic spokes configuration example<br />

This example demonstrates how to set up a basic route-based hub-and-spoke<br />

<strong>IPSec</strong> <strong>VPN</strong> that uses preshared keys to authenticate <strong>VPN</strong> peers.<br />

Figure 8:<br />

Example hub-and-spoke configuration<br />

Spoke_1<br />

Spoke_2<br />

Internet<br />

Site_1<br />

10.1.1.0/24<br />

Hub<br />

172.16.10.1<br />

<strong>FortiGate</strong>_1<br />

Site_2<br />

10.1.2.0/24<br />

HR Network<br />

10.1.0.0/24<br />

In the example configuration, the protected networks 10.1.0.0/24, 10.1.1.0/24 and<br />

10.1.2.0/24 are all part of the larger subnet 10.1.0.0/16. The steps for setting up<br />

the example hub-and-spoke configuration create a <strong>VPN</strong> among Site 1, Site 2, and<br />

the HR Network.<br />

The spokes are dialup. Their addresses are not part of the configuration on the<br />

hub, so only one spoke definition is required no matter the number of spokes. For<br />

simplicity, only two spokes are shown.<br />

<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />

42 01-30005-0065-20070716

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!