FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
HarshChavda
Staff
Staff
Article Id 330076
Description This article provides a step-by-step guide on configuring an aggregate IPsec tunnel interface using the GUI on FortiGate.  
Scope FortiGate.
Solution

Configuring an aggregate IPsec tunnel involves combining multiple IPsec tunnels into a single logical interface, which distributes traffic across the member tunnels for improved performance and redundancy. This guide will walk you through the necessary steps to set up an aggregate IPsec tunnel for both WAN interfaces on this site to the same remote site. 

 

In the diagram below, there are two WAN interfaces on this FortiGate and multiple IPsec tunnels to a single site from both WAN interfaces to a single remote gateway. 

 

Aggregate VPN img 1 .PNG

 

To configure an aggregate IPsec tunnel interface:

  1. Navigate to VPN -> IPsec Aggregate in the FortiGate interface.  
  2. Create a new IPsec Aggregate by selecting 'Create New' as shown in the image below.
  3. Configure the Aggregate VPN.

aggr 2 copy.PNG 

It is possible to assign a descriptive name and there will be four options for the algorithm. 

  1. Weighted Round Robin - Allocates traffic based on predefined weights, allowing more traffic to preferred tunnels. 
  2. L3 - Provides redundancy based on IP routing. 
  3. L4 - Provides redundancy based on port numbers and connection states. 
  4. Redundant – This is used to provide a backup in case the primary tunnel fails, ensuring continuous connectivity between sites.
     

aggr 4 copy.PNG

 

Both tunnels are pointing toward the same remote gateway, if it is desired to add both the tunnels to aggregate interface, it will be necessary to remove all the references to the IPSEC tunnels and to enable ‘set aggregate-member’ in the IPsec phase1 setting in CLI, by default it is disabled. Once enabled, it will be available to add. 

 

aggr 8 copy.PNG

 

Once both IPsec tunnels are available, it is possible to add it to the Aggregate interface as shown below. 

 

aggr 9Copy.PNG

 

Once both IPsec tunnels are added to the aggregate interface, they will be referenced under the aggregate interface as shown below. 

 

aggr 10 copy.PNG

 

It will be necessary then to configure a firewall policy for this new aggregate interface from the internal interface to the aggregate tunnel interface as shown below.


aggr 7 Copy.PNG

 

By following these steps, it is possible to successfully configure an aggregate IPsec tunnel using the FortiGate GUI, enhancing the redundancy and performance of the VPN connections.