Академический Документы
Профессиональный Документы
Культура Документы
FortiOS 5.6 is now available: Release Notes | What's New | Upgrade Path
EDUCATION / ENTERPRISE / FORTIOS 5.4 / FORTIOS 5.4.0 / FORTIOS 5.4.1 / FORTIOS 5.4.2 / FORTIOS 5.4.3 / VPNS
Sitetosite IPsec VPN with two FortiGates
Posted on January 27, 2016 by Adam Bristow
In this example, you will allow transparent communication between two networks that are located
behind different FortiGates at different of𠈁ces using route-based IPsec VPN. The VPN will be created
on both FortiGates by using the VPN Wizard’s Site to Site – FortiGate template.
In this example, one of𠈁ce will be referred to as HQ and the other will be referred to as Branch.
http://cookbook.fortinet.com/sitetositeipsecvpnwithtwofortigates54/ 1/5
4/16/2017 Sitetosite IPsec VPN with two FortiGates Fortinet Cookbook
5.2 | 5.4
1. Configuring the HQ IPsec VPN
In the Policy & Routing step, set the Local Interface. The Local Subnets will
be added automatically. Set Remote Subnets to the Branch FortiGate’s local
subnet (in the example, 5.5.5.5/24).
2. Configuring the Branch IPsec VPN
Set the same Pre-shared Key that was used for HQ’s VPN.
http://cookbook.fortinet.com/sitetositeipsecvpnwithtwofortigates54/ 2/5
4/16/2017 Sitetosite IPsec VPN with two FortiGates Fortinet Cookbook
In the Policy & Routing step, set the Local Interface. The Local Subnets will
be added automatically. Set Remote Subnets to the HQ FortiGate’s local
subnet (in the example, 10.10.10.1/24).
3. Results
A user on either of the of𠈁ce networks should be able to connect to any address on the other
of𠈁ce network transparently.
If you need to generate traf𠈁c to test the connection, ping the Branch FortiGate’s internal
interface from the HQ’s internal network.
About Latest Posts
Adam Bristow
Technical Writer at Fortinet
Adam Bristow is a Technical Writer working for the FortiOS technical documentation team.
He has a Honours Bachelor of Arts in English and Minor in Film Studies and a graduate
certi𠈁cate in Technical Writing from Algonquin College. Stay tuned for more FortiOS
Cookbook videos!
http://cookbook.fortinet.com/sitetositeipsecvpnwithtwofortigates54/ 3/5
4/16/2017 Sitetosite IPsec VPN with two FortiGates Fortinet Cookbook
Leave a Reply
Connect with:
Powered by OneAll Social Login
Join the discussion
How to do a redundant ISP at home of𠈁ce with remote fortigates (Single ISP). I
have redundant ISP at of𠈁ce, (Different IP networks) and remote clients. How do
you con𠈁gure the remote FG devices to use multiple IP to lookup and connect to
Home Of𠈁ce?
Hakim Mani
Hi, will site-to-site vpn work with older fortios like v4?
Kristian Villapando
Hi, will site-to-site ipsec vpn work with different fortiOS? 5.4.1 and 5.2.5?
http://cookbook.fortinet.com/sitetositeipsecvpnwithtwofortigates54/ 4/5
4/16/2017 Sitetosite IPsec VPN with two FortiGates Fortinet Cookbook
Keith Leroux
Hi Kristian,
Yes it will, and the procedure is nearly identical for both releases.
CONTACT | DOCUMENTATION LIBRARY | CLI PORTAL | FUSE | VIDEOS | SUPPORT | CORPORATE | LEGAL
© 2017 Fortinet
http://cookbook.fortinet.com/sitetositeipsecvpnwithtwofortigates54/ 5/5