Hi Guys
Can you give me a hand on this. I'm going to configure Fortigate (FortiWiFi 60C) to act as a remote-access VPN Client to Cisco ASA. How can I accomplish this. I'm new at Configuring Fortinet. Also we need to build Two Remote-access to 2 different locations. The first RA-VPN will pass to the WAN1 interface and the other RA-VPN will pass to the WAN2 interface. Please see topology below.
****** REMOTE-ACCESS VPN********
[FortiWifi 60C] WAN1------------[DSL Modem]-------->((( INTERNET )))-------------> [Cisco ASA 5520 BRANCH1]
WAN2----------------- [DSL Modem]-------->((( INTERNET )))-------------> [Cisco ASA 5520 BRANCH2]
*fortiwifi WAN1 and WAN2 Interfaces is connected to only 1 DSL Modem going to the internet
Thanks in advance... :)
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I would personally just build two IPSec tunnels.....on each WAN connection. (1 to each branch) and then let them provide fail over for one another. Either way, IPSec between the sites should be easy enough and reliable.
Mike Pruett
Some obstacles ahead:
- if you have control over the ASA's setup, configure site-to-site VPNs
- if not, on the FGT create "dial-up" VPNs, simulating a FortiClient.
Depending on the firmware version on the FGT, the VPN wizards will help you. The key point here is that IIRC Cisco provides the VPN settings for clients when they connect, called "mode-config". You'll have to get that into the config, via CLI if needed.
Dual WAN: this will depend on your routes. There should only be one default route, or one with higher priority. I'm sure you'll find plenty of examples here in the forums, or on Fortinet's site cookbook.fortinet.com .
Thanks for the reply.
Is it possible to have same Phase 2 for the separate IPSEC Tunnel for both WAN1 and WAN2.
e.g.
WAN1 = Local1 ----------> to Branch1
WAN2 = Local1 ----------> to Branch2
Is there a way that I can make the two VPN simultaneous, they are UP at the same time. If possible can you help me with the steps?.. Tnx
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.