Hi'
I'm going soon to install on our network central fortigate UTM, it will be connected with some mikrotik routers using ipsec.
Now I'm thinking how to connect it. As I have many networks, I wouldn't rather use legacy ipsec in tunnel mode.
If I choose ipsec in interface mode how then should I configure Mikrotik side, should it be GRE Ipsec Interface? Or maybe Ipsec interface mode can be configured only between Fortigate devices?
thanks for help.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi, I spent several days on this issue, but did not find a fully working solution. This is the hottest topic now in medium-sized business. Many people refuse to integrate FortiGate, so it is difficult to make friends with a MicrotiK.
How you configure the Fortigate has nothing to do with the remote end. They cannot tell if the FGT is in interface or tunnel mode. A tunnel is a tunnel as far as they know. I have broken down FGT tunnels in tunnel mode and brought them back up in interface mode. The credentials are the same. The difference boils down to a check box during creation. (Oh, and the routing definition and policy is different too)
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
To add, mikrotik vpn to fgt are well known. Take a look at this https://www.fastbit.ro/en/ipsec-site-to-site-vpn-between-fortigate-and-mikrotik/
Also, ipsec is an open standard.
Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.