Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

Set Up IPSec Site to Site VPN Between Fortigate 60D (2) - Policy-Based VPNs

4/14/2015

0 Comments

 
This is the second post for Fortigate IPSec VPN configuration. It will use same topology as previous one.

The implementation will be set up policy based IPSec VPN between two sites.

Topology:


Configuration Steps:

1. Enable Policy Based VPN feature:

By default, Policy-Based IPSec VPN feature is not enabled.  We will have to go to System-Config-Feature-Show More to enable it.

2. Go to: Firewall Objects > Address > Address


  • Create New Address – Internal Subnet - Name it as net_10.94.70.0_local
  • Enter local subnet: 10.94.70.0/24
  • Select internal interface

3. Create New Address – Remote Subnet - Name it as net_10.94.66.0_Remote


  • Enter Remote Subnet: 10.94.66.0/24
  • Enter wan1 Interface


4.  Go to Policy > Policy > Policy

  • Create New
  • Select VPN Policy Type
  • Select IPsec Subtype
  • Select the local interface - internal, and Local Protected Subnet net_10.94.70.0_local
  • Select the wan interface - wan1, and remote protected Subnet net_10.94.66.0_remote
  • Set service to all
  • Select create new VPN Tunnel.
  • Choose Site-to-Site and Name it as f1-f2
  • Put FW2's wan1 ip 10.94.17.8 as Remote FortiGate IP.
  • Enter Preshared Key
  • Check the box to allow traffic to be initiated from the remote site
Note: If you choose use Existing directly, sometimes, you will not see your pre-configured VPN tunnel in the list. Create a new vpn tunnel from here always works.

5. Move the policy to the top of the list

6. FW2's Configuration

a. FW2's Firewall Objects - Address-Addresses
There are three local networks defined in here, including all local subnets 10.94.64.0/24, 10.94.66.0/24 and 10.94.144.0/24
 b. Three policy rules defined for three different local networks. Remote destination network are same, which is 10.94.70.0/24. All those three rules are using same IPSec vpn tunnle f2-f1, which is defined in step 4.

7. Verify VPN Configuration and Monitoring VPN Tunnel

 Note: There is no phase 2 in the Auto Key (IKE) configuration.
Verified ping from 10.94.70.20 to 10.94.66.4

Reference:

  • Using policy-based IPsec VPN for communication between offices


0 Comments



Leave a Reply.

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org