Configuring IPsec VPN on HQ
Configuring IPsec VPN on HQ
- To create a new IPsec VPN tunnel, connect to HQ, go to VPN > IPsec Wizard, and create a new tunnel.
- In the VPN Setup step, set Template Type to Site to Site, set Remote Device Type to FortiGate, and set NAT Configuration to No NAT between sites.
- In the Authentication step, set IP Address to the public IP address of the Branch FortiGate (in the example, 172.25.177.46).
- After you enter the IP address, the wizard automatically assigns an interface as the Outgoing Interface. If you want to use a different interface, select it from the drop-down menu.
- Set a secure Pre-shared Key.
- In the Policy & Routing step, set Local Interface to lan. The wizard adds the local subnet automatically. Set Remote Subnets to the Branch network’s subnet (in the example, 192.168.13.0/24).
- Set Internet Access to None.
- A summary page shows the configuration created by the wizard, including interfaces, firewall addresses, routes, and policies.
- To view the VPN interface created by the wizard, go to Network > Interfaces.
- To view the firewall addresses created by the wizard, go to Policy & Objects > Addresses.
- To view the routes created by the wizard, go to Network > Static Routes.
- To view the policies created by the wizard, go to Policy & Objects > IPv4 Policy.
Configuring IPsec VPN on HQ
Configuring IPsec VPN on HQ
- To create a new IPsec VPN tunnel, connect to HQ, go to VPN > IPsec Wizard, and create a new tunnel.
- In the VPN Setup step, set Template Type to Site to Site, set Remote Device Type to FortiGate, and set NAT Configuration to No NAT between sites.
- In the Authentication step, set IP Address to the public IP address of the Branch FortiGate (in the example, 172.25.177.46).
- After you enter the IP address, the wizard automatically assigns an interface as the Outgoing Interface. If you want to use a different interface, select it from the drop-down menu.
- Set a secure Pre-shared Key.
- In the Policy & Routing step, set Local Interface to lan. The wizard adds the local subnet automatically. Set Remote Subnets to the Branch network’s subnet (in the example, 192.168.13.0/24).
- Set Internet Access to None.
- A summary page shows the configuration created by the wizard, including interfaces, firewall addresses, routes, and policies.
- To view the VPN interface created by the wizard, go to Network > Interfaces.
- To view the firewall addresses created by the wizard, go to Policy & Objects > Addresses.
- To view the routes created by the wizard, go to Network > Static Routes.
- To view the policies created by the wizard, go to Policy & Objects > IPv4 Policy.