Hello there,
I will briefly explain my problem. I have a firewall Fortigate 60D and I need to create a tunner to a L2TP/IPSEC server, so the firewall has to act as a client.
Is it possible? if yes, how can I configure the firewall?
I configured the L2TP/IPSEC server on a debian machine and I can connect to it using an android phone but I am not able to do the same with the Fortigate firewall.
This is my server ipsec.conf
version 2.0
config setup
dumpdir=/var/run/pluto/
nat_traversal=yes
virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:!10.10.6.0/24
oe=off
protostack=netkey
nhelpers=0
interfaces=%defaultroute
conn vpnpsk
connaddrfamily=ipv4
auto=add
left=public_server_ip
leftid=public_server_ip
leftsubnet=public_server_ip/32
leftnexthop=%defaultroute
leftprotoport=17/1701
rightprotoport=17/%any
right=%any
rightsubnetwithin=0.0.0.0/0
forceencaps=yes
authby=secret
#xauthby=pam
#authby=never
#xauthby=alwaysok
#aggrmode=yes
#ikev2=never
pfs=no
type=transport
auth=esp
ike=3des-sha1,aes-sha1
#ike=3des-sha1
phase2alg=3des-sha1,aes-sha1
#phase2alg=3des-sha1
rekey=no
keyingtries=5
dpddelay=30
dpdtimeout=120
dpdaction=clear
Thank you
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.