Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Putmano
New Contributor

Move the IPS VPN from Fortigate to Fortimanager

Currently I have 2 FortiGate 600D running for VPN gateway in my infrastructure with 80 active tunnels. We just bought Fortimanager and we want to manage VPN on FortiGate but I cannot import the VPN Tunnel on FortiGate to the FortiManager.

I have enabled VPN Central Management on FortiManager. However it sill cannot see the tunnels on FortiManager.  Have anybody experiences with VPN on FortiManager?

Thanks in advance. 

3 Solutions
ergotherego
Contributor II

I wouldn't recommend using the Central VPN Manager tool for IPSec VPNs personally. It's too limited in my opinion, and knowing FMG there are likely some bugs in it since its more of an edge-case feature.

 

You can still manage your IPSec VPNs directly under the Device itself, which lets you manage each tunnel individually just like you would on a FGT.

 

You probably need to adjust your Display Settings first:

 

Device Manager > Tools > Global Display Options

 

Then under the section for VPN make sure IPSec Phase 1 and 2 are enabled.

 

Inside Device Manager, you can double-click on your firewall to enter its configuration page (these are the device level settings). You will now see an option for VPN in the grey menu bar.

 

Note: Even with VPN Central Manager disabled for a given ADOM, you still use it to manage SSLVPN.

View solution in original post

chall_FTNT

> we want to manage VPN on FortiGate but I cannot import the VPN Tunnel on FortiGate to the FortiManager.

 

Unless you are running FMG 5.6.0 or later, using VPN Central Manager does not support preexisting VPN tunnels.  In this mode, all tunnels must be created by the FortiManager.  VPN tunnels configured prior to enabling VPN central management will be removed.

 

If FMG 5.6.0 or later, enabling VPN Central Manager will not affect existing VPN tunnels.

 

So this may not fit your situation.  That said, VPN Central Manager can greatly simplify large scale VPN deployments and there is no reason to shy away from it provided it meets your requirements.

Chris Hall
Fortinet Technical Support

View solution in original post

linfante
New Contributor II

I could be wrong, but you'll need to recreate them in the FMG VPN Manager first and then apply the VPNs to the FG in FMG. That's the plan we have anyhow. It made mention of deleting all the VPNs if we turned on the VPN Manager with the FG already added to FMG so the FG was removed from FMG, and then VPN Manager turned on so that VPNs could be recreated.

View solution in original post

3 REPLIES 3
ergotherego
Contributor II

I wouldn't recommend using the Central VPN Manager tool for IPSec VPNs personally. It's too limited in my opinion, and knowing FMG there are likely some bugs in it since its more of an edge-case feature.

 

You can still manage your IPSec VPNs directly under the Device itself, which lets you manage each tunnel individually just like you would on a FGT.

 

You probably need to adjust your Display Settings first:

 

Device Manager > Tools > Global Display Options

 

Then under the section for VPN make sure IPSec Phase 1 and 2 are enabled.

 

Inside Device Manager, you can double-click on your firewall to enter its configuration page (these are the device level settings). You will now see an option for VPN in the grey menu bar.

 

Note: Even with VPN Central Manager disabled for a given ADOM, you still use it to manage SSLVPN.

chall_FTNT

> we want to manage VPN on FortiGate but I cannot import the VPN Tunnel on FortiGate to the FortiManager.

 

Unless you are running FMG 5.6.0 or later, using VPN Central Manager does not support preexisting VPN tunnels.  In this mode, all tunnels must be created by the FortiManager.  VPN tunnels configured prior to enabling VPN central management will be removed.

 

If FMG 5.6.0 or later, enabling VPN Central Manager will not affect existing VPN tunnels.

 

So this may not fit your situation.  That said, VPN Central Manager can greatly simplify large scale VPN deployments and there is no reason to shy away from it provided it meets your requirements.

Chris Hall
Fortinet Technical Support
linfante
New Contributor II

I could be wrong, but you'll need to recreate them in the FMG VPN Manager first and then apply the VPNs to the FG in FMG. That's the plan we have anyhow. It made mention of deleting all the VPNs if we turned on the VPN Manager with the FG already added to FMG so the FG was removed from FMG, and then VPN Manager turned on so that VPNs could be recreated.

Labels
Top Kudoed Authors