Description | This article describes how to set up an IPsec VPN between FortiGate and Mikrotik using IKEv2. |
Scope | Applicable to all FortiGate versions and Mikrotik RouterOS 7.6 and beyond |
Solution |
Network diagram:
Configuration FortiGate: Create IPsec phases and tunnels.
RouterOS Configuration using Winbox:
Monitoring the status of the IPsec Tunnel on FortiGate and Mikrotik:
FortiGate:
Mikrotik:
Test the remote end connectivity. The IPsec site-to-site VPN is confirmed to be up; however, traffic must be initiated to verify whether it is functioning correctly.
To test connectivity from the MikroTik LAN side:
If it is configured correctly, an ICMP response will be received. Otherwise, a timeout will occur. In this case, an ICMP response is received, indicating that the tunnel is up and operational. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.