FortiGate SDWAN with IPsec VPN
ฝัง
- เผยแพร่เมื่อ 16 มิ.ย. 2024
- This tutorial teaches how to configure SD-WAN between two locations with IPsec VPN tunnels as SD-WAN zone members on FortiGate.
--------- Contents of this Video ---------
00:00 Introduction
01:14 SD-WAN Zone and Members
02:29 Configure VPN Tunnels
03:21 Configure Static Routes
03:50 Configure Firewall Policies
05:02 Create SD-WAN Performance SLA
05:53 Configure Ping SLA Source
06:46 Configure SD-WAN Rules
08:00 SD-WAN Zone and Members
09:17 Configure VPN Tunnels
09:55 Configure Static Routes
10:28 Configure Firewall Policies
11:30 Create SD-WAN Performance SLA
11:53 Configure Ping SLA Source
12:34 Configure SD-WAN Rules
13:16 Testing
14:48 Conclusion
If you have any questions or need further assistance, please feel free to leave a comment below. Don’t forget to subscribe to our channel for more helpful tutorials. - วิทยาศาสตร์และเทคโนโลยี
I will assume you programmed the remote network and local network subnet group prior to all this? And that you had to do this on both sides of the office? Also, what model is this Forigate? Do the entry models handle this much processing services?
Hi 01:45 is this pre-shared key is the same as configured in IPSec tunnel already? So same key we'll put here?
The pre-shared key was the same for all gateways
hi, thanks for this nice video, are you able to share relevant cfg in cli format though?
Thanks for enjoying the video. Unfortunately we do not have the cli configuration. We will share when we redo this lab.
This option to create vpn from sdwan zone doesn't appear in my fortigate what version do you use it ?
For source ip at sdwan members, need to use gateway ip of remote lan network ?
Source IP for SDWAN members should be one of the IP addresses in the encryption domain (traffic selector) of the VPN
What if we have multiple spokes ? With multiple internet connections.
See this video tutorial: th-cam.com/video/zkaDwPqZU_k/w-d-xo.html
If i configure in production firewall, is it possible internet down ?
Please come again. We didn't get your question well
Do I need to setup the VPN tunnel ip or not?
a VPN tunnel IP is required if you want to configure a dynamic routing protocol over the tunnel