Fortinet black logo

Cookbook

Configuring IPsec VPN on Branch

Copy Link
Copy Doc ID a4a06ec3-12a7-11e9-b86b-00505692583a:616440
Download PDF

Configuring IPsec VPN on Branch

  1. To create the tunnel on Branch, connect to Branch, and go to VPN > IPsec Tunnels and create a new tunnel.
  2. In the VPN Setup step, set Template Type to Custom and enter VPN-to-HQ for the Name.

  3. Enter HQ’s public IP address (in the example, 172.25.176.142) for the IP Address, and select Branch’s WAN interface for Interface (in the example, wan1).

  4. Enter a matching secure key for the Pre-shared Key.

  5. Type the new address ranges selected in the "Planning the new addressing scheme" section for Branch and HQ’s LAN in the Local Address and Remote Address fields (in the example, 10.2.2.0/24 and 10.1.1.0/24, respectively). The Local and Remote Address fields are the reverse of what you created in the "Configuring the IPsec VPN on HQ" section.

  6. Optionally, expand Advanced and enable Auto-negotiate.

Configuring IPsec VPN on Branch

  1. To create the tunnel on Branch, connect to Branch, and go to VPN > IPsec Tunnels and create a new tunnel.
  2. In the VPN Setup step, set Template Type to Custom and enter VPN-to-HQ for the Name.

  3. Enter HQ’s public IP address (in the example, 172.25.176.142) for the IP Address, and select Branch’s WAN interface for Interface (in the example, wan1).

  4. Enter a matching secure key for the Pre-shared Key.

  5. Type the new address ranges selected in the "Planning the new addressing scheme" section for Branch and HQ’s LAN in the Local Address and Remote Address fields (in the example, 10.2.2.0/24 and 10.1.1.0/24, respectively). The Local and Remote Address fields are the reverse of what you created in the "Configuring the IPsec VPN on HQ" section.

  6. Optionally, expand Advanced and enable Auto-negotiate.