FortiGate IPSec VPN User Guide - FirewallShop.com
FortiGate IPSec VPN User Guide - FirewallShop.com
FortiGate IPSec VPN User Guide - FirewallShop.com
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Dynamic spokes configuration example<br />
Hub-and-spoke configurations<br />
Action<br />
NAT<br />
Select ACCEPT<br />
Enable<br />
Source Interface/Zone Select the spoke’s interface to the internal (private) network.<br />
Source Address Name Select this spoke’s address name.<br />
Destination Interface/Zone Select the virtual <strong>IPSec</strong> interface you created.<br />
Destination Address Name Select the spoke address group you defined in Step 1.<br />
Action<br />
NAT<br />
Select ACCEPT<br />
Enable<br />
3 Place this policy or policies in the policy list above any other policies having similar<br />
source and destination addresses.<br />
Dynamic spokes configuration example<br />
This example demonstrates how to set up a basic route-based hub-and-spoke<br />
<strong>IPSec</strong> <strong>VPN</strong> that uses preshared keys to authenticate <strong>VPN</strong> peers.<br />
Figure 8:<br />
Example hub-and-spoke configuration<br />
Spoke_1<br />
Spoke_2<br />
Internet<br />
Site_1<br />
10.1.1.0/24<br />
Hub<br />
172.16.10.1<br />
<strong>FortiGate</strong>_1<br />
Site_2<br />
10.1.2.0/24<br />
HR Network<br />
10.1.0.0/24<br />
In the example configuration, the protected networks 10.1.0.0/24, 10.1.1.0/24 and<br />
10.1.2.0/24 are all part of the larger subnet 10.1.0.0/16. The steps for setting up<br />
the example hub-and-spoke configuration create a <strong>VPN</strong> among Site 1, Site 2, and<br />
the HR Network.<br />
The spokes are dialup. Their addresses are not part of the configuration on the<br />
hub, so only one spoke definition is required no matter the number of spokes. For<br />
simplicity, only two spokes are shown.<br />
<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />
42 01-30005-0065-20070716