Fortinet: How to Setup a Route-Based IPSec VPN Tunnel on a FortiGate Firewall

แชร์
ฝัง
  • เผยแพร่เมื่อ 1 เม.ย. 2020
  • When it comes to remote work, VPN connections are a must. But they come in multiple shapes and sizes.
    Join Firewalls.com Network Engineer Matt as he shows you how to setup a route-based IPSec VPN tunnel on a Fortinet FortiGate firewall to offer a secure work from home option on your network.
    Learn more about Fortinet: www.firewalls.com/brands/fort...
    And get a primer on FortiClient Endpoint Protection's offerings for remote work www.firewalls.com/blog/fortic...
  • แนวปฏิบัติและการใช้ชีวิต

ความคิดเห็น • 63

  • @firewallsDotCom
    @firewallsDotCom  2 ปีที่แล้ว

    For assistance please visit our website for support www.firewalls.com/wd/firewall-configuration/

  • @JR34MZ
    @JR34MZ 4 ปีที่แล้ว +9

    This helped me greatly as my team is very new to Fortigate. I genuinely appreciate your time on this one!

    • @firewallsDotCom
      @firewallsDotCom  4 ปีที่แล้ว +1

      Glad we could help! Thanks very much for the feedback, and for watching!

  • @AaronMichaelLong
    @AaronMichaelLong 4 วันที่ผ่านมา +1

    This is not a route-based VPN, this is a policy-based VPN configuration. The fact that you're identifying specific phase 2 proxy-IDs/selectors is what makes it policy-based.

  • @yushis
    @yushis 2 ปีที่แล้ว +2

    Awesome video. I'm coming from Watchguard so this is a new experience for me. Straight and to the point.

  • @richhughsam6464
    @richhughsam6464 2 ปีที่แล้ว +3

    This is a very good video, put together clear and concise. Well done!

    • @firewallsDotCom
      @firewallsDotCom  2 ปีที่แล้ว

      Thanks very much for the feedback, and for watching!

  • @lostinvasion
    @lostinvasion 4 หลายเดือนก่อน +1

    this helped me out a lot, thanks for sharing!

  • @_eurosign
    @_eurosign 2 ปีที่แล้ว +2

    Couldn’t be simpler than this. Many thanks.

    • @firewallsDotCom
      @firewallsDotCom  2 ปีที่แล้ว +1

      Thanks for sharing that feedback, and appreciate you watching!

  • @user-gh2ux7bh8b
    @user-gh2ux7bh8b ปีที่แล้ว +1

    You did save my day man, thanks a lot for a very good explanation! Thank you God bless you.

  • @ambadaschankhore2714
    @ambadaschankhore2714 4 ปีที่แล้ว

    Great Video..Thank you for sharing good knowledge.

  • @saiswaroop1989
    @saiswaroop1989 2 ปีที่แล้ว +7

    Hello, you said it's route based and but added local and remote subnets in interested traffic. Can you clarify?

  • @Wael_Fakhri
    @Wael_Fakhri ปีที่แล้ว

    very good video, Well done!

  • @adnaansiddiqi8772
    @adnaansiddiqi8772 3 ปีที่แล้ว +9

    Shouldn't route-based VPN be any network through tunnels and then control through the routing protocol which networks to allow?

  • @juancz4886
    @juancz4886 8 หลายเดือนก่อน

    Thanks Matt!

  • @pavelky8833
    @pavelky8833 3 ปีที่แล้ว

    Thanks dude !!!

  • @adetutuogunsowo7939
    @adetutuogunsowo7939 3 ปีที่แล้ว +1

    Can one implement a VPN tunnel on the LAN, two machines on different switches and VLANs but where inter-vlan routing happens at the layer 3 Fortinet FW? Thanks for your response

  • @conorpodonoghue
    @conorpodonoghue 11 หลายเดือนก่อน

    Thanks for this. What would be really helpful is a network diagram.

  • @MrKarlbarat
    @MrKarlbarat 4 ปีที่แล้ว

    thanks for the help, maybe later you can make a video how to setup a site to site vpn with aws

  • @capcata
    @capcata 3 ปีที่แล้ว +26

    This is NOT A routed VPN. This is a normal vpn.

  • @rockinron5113
    @rockinron5113 ปีที่แล้ว

    Nice one! Cheers

  • @v1c81
    @v1c81 4 ปีที่แล้ว

    I want a branch to make a dual vpn to my hq with wan1 and wan2 in sdwan. Do you have a video for that. Keeps saying duplicate exists.

  • @MohammedAli-pf2oc
    @MohammedAli-pf2oc 2 ปีที่แล้ว

    Amazing, just one more question on 3:20 what u did again exactly and why??

  • @romandavydov8684
    @romandavydov8684 2 ปีที่แล้ว

    Thank you for the tutorial. I have a question.
    My ISP is using L2TP IPsec for connection to internet.
    Curently I am using a zyxel router to connect to ISP internet. my fortigate is connected to the router now.
    I would like to connect my fortigate to the ISP directly. Cable from ISP directly to the fortigate.
    How can I configyre my wan connection as L2TP IPsec to connect to the internet?
    Please give me a piece of advice.
    Thank you

  • @Spegarinos
    @Spegarinos 3 ปีที่แล้ว +1

    If we have a profile based firewall what is the difference in the settings ?

  • @chuckjamm
    @chuckjamm 3 ปีที่แล้ว

    have you setup a route based vpn between fortigate and asa?

  • @stnkubinka
    @stnkubinka 2 ปีที่แล้ว

    If I have two peers at remote device (two ISP - main and reserve), how can I set second peer on Phase 1 on FortiGate?

  • @Nubsauce
    @Nubsauce ปีที่แล้ว

    how do you get the actual site to site tunnel to work and have the central fortigate share its internet with the remote fortigate?

  • @zizolibob
    @zizolibob 2 ปีที่แล้ว

    Very helpful!
    Can you please explain us why you disabled NAT on both policy rules?

    • @mustafamzale6597
      @mustafamzale6597 ปีที่แล้ว +1

      NAT is optional, it depend what is the remote subnet is. If the remote subnet is different with your subnet you can disable so real IP is reaching remote site. But it is advised to NAT and use public IP incase you are integrating with multiple sites. it will avoid LAN overlap

  • @the3cobblers683
    @the3cobblers683 2 ปีที่แล้ว

    Thought we should build a full 0.0.0.0/0 subnet both side for route based VPN?

  • @thomasjoseph9609
    @thomasjoseph9609 2 ปีที่แล้ว

    it is help me alot

  • @FRZ2012
    @FRZ2012 3 ปีที่แล้ว

    Many thanks

    • @firewallsDotCom
      @firewallsDotCom  3 ปีที่แล้ว

      Many thanks to you too for watching and commenting!

  • @TWInter-fb6wo
    @TWInter-fb6wo 2 ปีที่แล้ว

    I Can ' Remote Router Site B When Connect With forticlient ipsec But Remote Site A Can Be Used

  • @MadalinVladescu
    @MadalinVladescu 3 ปีที่แล้ว

    can you show us how to route all internet traffic through the Fortigate? thank for you videos

    • @cr7fanatics792
      @cr7fanatics792 2 ปีที่แล้ว

      Disable split tunnel in ipsec.. Then all the internet traffic will be routed through fortigate.

  • @princepolitely7559
    @princepolitely7559 2 ปีที่แล้ว

    Hello,
    I am trying to configure IPsec VPN with Fortigate 300e firewall but couldn't succeed.
    Can anyone help me in configuring the VPN from NGAF AF-1000 to Fortigate 300e?
    also on 300e. i don't have ipv4 policy option. (Policy & Objects -> ipv4 policy)

  • @schampion3
    @schampion3 3 ปีที่แล้ว

    It would be helpful to post the corollary of setting up a Sonicwall TZxxx to work with a route based Fortigate IPSEC VPN Tunnel.

    • @arunparthan
      @arunparthan 11 หลายเดือนก่อน

      th-cam.com/video/nEEA09fBZ1Q/w-d-xo.html

  • @georgemandilas896
    @georgemandilas896 2 ปีที่แล้ว

    Hi
    locally i can connect but from my job it can not connect

  • @hoangtruong7166
    @hoangtruong7166 2 ปีที่แล้ว

    What is head office and branch office have several VLAN

  • @doctor.networks
    @doctor.networks 2 ปีที่แล้ว +4

    Great Video. Just one thing, This is a POLICY Based VPN not a ROUTE based VPN, a Route Based VPN is something like a GRE over IPsec or VTI tunnel. Something on which routing protocols can work.

    • @cheong4141
      @cheong4141 ปีที่แล้ว

      r u using Cisco concept to estimate Fortigate? anyway, pls view it as vti.

  • @chunkityeong5225
    @chunkityeong5225 4 ปีที่แล้ว

    Will it work if we leave the local and remote address as 0.0.0.0(any)? or we must specify? thanks.

    • @evexs98
      @evexs98 4 ปีที่แล้ว

      Use administrative distance, be cause you need 0.0.0.0/0 to use internet.

  • @unknownwolf4046
    @unknownwolf4046 3 ปีที่แล้ว

    I have 4G Router bec mx210np R17 I setup Ipsec but wont connect

  • @amarabaz6147
    @amarabaz6147 2 ปีที่แล้ว +1

    Hello there. One question can I use it like this to make a tunnel towards NordVPN. I have a FortiGate 100E ?

    • @firewallsDotCom
      @firewallsDotCom  2 ปีที่แล้ว

      IPsec is an open standard and should work with any vendor that supports it. Thanks for your comment and be sure to subscribe for new content.

  • @xtwist3779
    @xtwist3779 ปีที่แล้ว

    give me link to this fortigate soft

  • @gre1677
    @gre1677 2 ปีที่แล้ว +2

    I think this is for policy based vpn tunnel not a route based. anyway thank you for your videos :)

  • @m0rphe0-8
    @m0rphe0-8 2 ปีที่แล้ว +1

    why is needed static route ?

    • @firewallsDotCom
      @firewallsDotCom  2 ปีที่แล้ว

      You need to have a static route so that the firewall knows who to send what traffic to. You can use a static route or dynamic routing protocols such as OSPF as well. Thanks for your comment and be sure to subscribe for new content.

  • @svbakulin
    @svbakulin 2 หลายเดือนก่อน +1

    This is not route based VPN, it is an old school policy VPN.

  • @cason4468
    @cason4468 2 ปีที่แล้ว

    it was amazing, but it could be better with a less tired voice

  • @bschelst
    @bschelst 3 ปีที่แล้ว

    That's policy based tunnel,not route based tunnel

  • @iphelper1574
    @iphelper1574 หลายเดือนก่อน +1

    Misguided tutorial. Should have been named as policy-based VPN