VPNs and Zones?
I'm new to Fortigate and am trying to mirror a setup that we've successfully deployed across hundreds of firewalls from from a couple different vendors. We spoke with support regarding this, but my level of confidence in the conversation is low, so i'd like to run it the forum for a second opinion...
We have "spoke" locations that terminate tunnels to two "hub" locations, one primary and one backup.
We'd typically build route based tunnels and put VPN_1 and VPN_2 into the same zone (VPN) our firewall policies and address objects would then be based on the LAN and VPN zones:
LAN > VPN
VPN > LAN
The support tech we spoke with, suggested that a fortigate will not support the above setup (that we cannot group VPN interfaces into a single zone), which means we'd have to do something like:
LAN > VPN_1
LAN > VPN_2
VPN_1 > LAN
VPN_2 > LAN
The problem is that on many of the firewalls we're looking at, we're talking hundreds, if not thousands, of address objects (including groups) and hundreds of firewall policies that would have to be duplicated.
At the end of the day, I suppose it's not THAT much work to duplicate the configs... we'd just build one config that would be based on VPN_1, then find-replace instances of VPN_1 with VPN_2 (and renumber policies as needed), but that seems like a inefficient process and also one that increases the potential for error.
Can anyone comment regarding the viability of grouping VPN interfaces into the same zone and how to make it work (if it's possible)?
Thank you in advance,
Chris
