Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zoki
New Contributor

Establishing IPsec

Hello, I'm trying to set up a lab, and I want to inquire if it's possible to do this. I have an FG40 that is remote. From my home, I set up a FortiGate virtual to establish an IPsec connection. However, I've read in several places that both FortiGates must first have a conversation for the tunnel to come up. If so, how is it possible to establish that policy so that both FortiGates can see each other and share the connection? I hope I was clear.

4 REPLIES 4
AEK
SuperUser
SuperUser

Hi

You can understand it and achieve it if you follow this guide.

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/520377/ipsec-vpns

AEK
AEK
hbac
Staff
Staff

Hi @Zoki,

 

If both FortiGates are not in the same location, they need Internet access in order to communicate with each other. If FortiGate is behind NAT, you need to configure port forwarding on the ISP side. 

 

Regards, 

Zoki
New Contributor

Excuse my ignorance, but what port should it be directed to on the router?

hbac

@Zoki,

 

The router should forward port 500 and 4500 to the FortiGate. 

 

Regards, 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors