Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Israt24Fortinet
New Contributor

FortiGate IPSec VPN

Hello! I have a question regarding IPSec VPN. There are 2 firewall, FortiGate 60F (site A) and 200F (Site B). The question is, do I need to configure IPSec VPN for routers in Site A and Site B if the router is either before or after the FortiGate firewall?

1 Solution
ozkanaltas
Valued Contributor III

Hello @Israt24Fortinet ,

 

If your FortiGate communicates (via internet or local connection) with each other you can configure the IPsec tunnel on FortiGate. No need to configure ipsec on your router. 

 

 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
3 REPLIES 3
ozkanaltas
Valued Contributor III

Hello @Israt24Fortinet ,

 

If your FortiGate communicates (via internet or local connection) with each other you can configure the IPsec tunnel on FortiGate. No need to configure ipsec on your router. 

 

 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Israt24Fortinet

Thanks for the response. Regarding IPSec where I configured, the problem I am facing is the 2 firewall can communicate (ping) but each of their LAN can not communicate with the firewall. Also IPSec VPN phase 1 is still down. I have followed all the documentation regarding configuration. Any thoughts on this like what could be the problem?

ozkanaltas

Hello @Israt24Fortinet ,

 

If your router acts like a nat device for your FortiGate. You need to configure nat traversal on your IPSec configuration. Or you need to configure dnat for udp/500 port on your router.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPSec-VPN-nattraversal/ta-p/197873

 

IPsec configuration is not enough for Fortigate. You should configure route and policy on your FortiGate. 

 

Also, you can find the troubleshooting step in this link. 

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPNs-tunnels/ta-p/195955

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPSEC-Tunnel-debugging-IKE/ta-p/1900...

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Understanding-IPsec-iked-debug-logs/ta-p/2...

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors