FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
vbandha
Staff
Staff
Article Id 275651
Description This article is a resource list for FortiGate IPSec VPN Configuration and Troubleshooting.
Scope FortiGate v7.0+.
Solution

 Configuration:

Title Description

Basic site-to-site VPN with pre-shared key

Configuration for Site-to-Site IP Sec Tunnel.
Site-to-site VPN with overlapping subnets:  Site-to-site tunnel configuration with the same private subnet on both sides.
Configuring IPSec VPN tunnels on VDOMs that do not have a WAN connection  Configuration guide for IP Sec tunnel in multi VDOM environment when the VDOM does not have a WAN connection.
Dynamic routing (BGP) over IP Sec Tunnel  Configuring BGP over IP Sec Tunnel.
Policy Based IP Sec VPN  Configuring Policy Based IP Sec VPN.

 

Troubleshooting:

Troubleshoot Site to Site tunnel connectivity  Comprehensive troubleshooting guide for Site to Site IP Sec tunnel.
Disable NP Offloading  Disabling NP offloading for individual IPsec VPN phase 1s.
IPSEC Anti-replay and preventing packet drops  Explanation for IP Sec Anti replay on how it prevents packet drops.
Troubleshoot speed or bandwidth issues in Site-to-Site IP Sec VPN  Troubleshooting steps for speed or bandwidth issues. 

 

Contributors