Skip to main content
Zoki
New Member
February 20, 2024
Question

Establishing IPsec

  • February 20, 2024
  • 2 replies
  • 1435 views

Hello, I'm trying to set up a lab, and I want to inquire if it's possible to do this. I have an FG40 that is remote. From my home, I set up a FortiGate virtual to establish an IPsec connection. However, I've read in several places that both FortiGates must first have a conversation for the tunnel to come up. If so, how is it possible to establish that policy so that both FortiGates can see each other and share the connection? I hope I was clear.

2 replies

AEK
SuperUser
SuperUser
February 20, 2024

Hi

You can understand it and achieve it if you follow this guide.

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/520377/ipsec-vpns

AEK
hbac
Staff
Staff
February 20, 2024

Hi @Zoki,

 

If both FortiGates are not in the same location, they need Internet access in order to communicate with each other. If FortiGate is behind NAT, you need to configure port forwarding on the ISP side. 

 

Regards, 

Zoki
ZokiAuthor
New Member
February 21, 2024

Excuse my ignorance, but what port should it be directed to on the router?

hbac
Staff
Staff
February 22, 2024

@Zoki,

 

The router should forward port 500 and 4500 to the FortiGate. 

 

Regards,