Created on
03-28-2025
08:02 AM
Edited on
04-01-2025
11:05 PM
By
Jean-Philippe_P
Description | This article describes how to configure S2S IPsec VPN between FortiGate device and Opnsense appliance. |
Scope | FortiOS. |
Solution |
The lab environment consists of 1 FortiGate and 1 Opnsense device, both installed as virtual appliances on top of Hyper-V More details on how to install FortiGate VM on Hyper-V can be found at this link: Technical Tip: Install FortiGate-VM on Hyper-V and apply Permanent Trial License
Steps on how to set up Opnsense on top of Hyper-V can be found in the vendor knowledge base. This article does not cover this topic. Below are the configurations that should be checked prior to setup ipsec tunnel.
Setup Opnsense:
config vpn ipsec phase1-interface set comments "VPN: ToOpnsense (Created by VPN wizard)" set dhgrp 14 set wizard-type static-fortigate set remote-gw 192.168.178.96 set psksecret ENC ****** next end
Phase2 interface:
Note that if private IP ranges are used for testing purposes, Opensense will block them unless 'Block private networks' under Interfaces –> WAN is disabled.
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.