Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ehsangha
New Contributor II

Fortigate Policy for IPsec

Greetings, all. I have 60 site-to-site IPsec tunnels, and in order to create a policy for each one, I will need to write numerous policies due to the varied zones. I am inquiring as to what the most effective practices are at this time. Should I establish Zones or Interface Groups or enable multiple interface policies?

4 REPLIES 4
Toshi_Esumi
SuperUser
SuperUser

If all IPsec site-to-site VPN need to have the same policy, which is most likely the case, you can put all of them in one zone so that you need to have only one pair of policies, inbound and outbound, for all IPsecs. That's what we do for hundreds of IPsecs per our customer.

Toshi

makilra2
New Contributor

Having the same issue. Add user and “all” for the IP object under source, but no dice. Tried adding the IPSec subnet too, still no go. Does it not work for local users?

jiahoong112

what do you mean by this? could you please provide a screenshot?

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
jiahoong112
Staff
Staff

I'd suggest going for Zones in your case: https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/116821/zone 

If you go with Multiple Interface Policies, it can get messy very quickly. Please keep in mind that to add an ipsec tunnel to a Zone, it must not yet be referenced by any other firewall policies. 

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors