FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
lfernando
Staff
Staff
Article Id 388563
Description This article explains how to configure an IPsec tunnel Remote Access using Wizard in FortiGate v7.6.x and lower 7.x.x versions.
Scope

FortiGate 7.2.x, and 7.0.

FortiClient 7.4.3.
Solution

Scenario:

 

vpn1.jpg

 

Create an IPsec VPN with the VPN Wizard on FortiGate:

  • Select the VPN type (Remote Access was chosen in this case).

  • Use a client pool with approximately 20 IP addresses:

    • Pool range: 192.168.100.20 to 192.168.100.40

 

Version 7.6.2:

 

vpn2.jpg

vpn4.jpg
vpn3.jpg

 

The incoming interface (connected to the Internet) and the local interface (connected to the LAN) must be declared. A pool for remote user connections must be created, along with user/group access for remote connections. The Split Tunneling option ensures internal resources remain reachable.

 

vpn5.jpg

Configure the IPsec VPN parameters and policies, then validate the configuration.

 

vpn6.jpg

 

vpn7.jpg

Lower versions than 7.6.x.

 

The configuration remains similar to version 7.6.x, but the GUI differs (e.g., classic view in 7.4.7).

 

vpnA.jpg

vpn B.jpg

vpn C.jpg

After using the VPN Wizard, navigate to VPN -> IPsec Tunnels and double-click the VPN to verify parameters. Ensure XAUTH is enabled in the wizard to match the user group for VPN access.

 

vpn D.jpg

 

Phase 2 Selector Parameters:

  • Proposals: AES-256, SHA-256.

  • Diffie-Hellman Group: 5.

 

vpn E.jpg

 

vpnF.jpg

Configuration Validation:

Use FortiClient 7.4.3 (compatible with these FortiGate versions).

Replicate same parameters on it. 

 

vpnG.jpg

Parameters on FortiClient:

 

vpnH.jpg

 

VPN I.jpg

 

Testing Connectivity:

 

On a Windows device:

  • Ping the LAN's default gateway behind the FortiGate.

  • Execute route print to confirm the internal segment is reachable via the VPN pool IP.

 

A.jpg

B.jpg

C.jpg

 

Related articles:

Comments
MaryBolano
Staff
Staff

Excellent @lfernando ! keep it up!

lpedraza
Staff
Staff

Great job Fernando! thank you so much for your valuable contribution! @lfernando 

 

Contributors