Currently I have 2 FortiGate 600D running for VPN gateway in my infrastructure with 80 active tunnels. We just bought Fortimanager and we want to manage VPN on FortiGate but I cannot import the VPN Tunnel on FortiGate to the FortiManager.
I have enabled VPN Central Management on FortiManager. However it sill cannot see the tunnels on FortiManager. Have anybody experiences with VPN on FortiManager?
Thanks in advance.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I wouldn't recommend using the Central VPN Manager tool for IPSec VPNs personally. It's too limited in my opinion, and knowing FMG there are likely some bugs in it since its more of an edge-case feature.
You can still manage your IPSec VPNs directly under the Device itself, which lets you manage each tunnel individually just like you would on a FGT.
You probably need to adjust your Display Settings first:
Device Manager > Tools > Global Display Options
Then under the section for VPN make sure IPSec Phase 1 and 2 are enabled.
Inside Device Manager, you can double-click on your firewall to enter its configuration page (these are the device level settings). You will now see an option for VPN in the grey menu bar.
Note: Even with VPN Central Manager disabled for a given ADOM, you still use it to manage SSLVPN.
> we want to manage VPN on FortiGate but I cannot import the VPN Tunnel on FortiGate to the FortiManager.
Unless you are running FMG 5.6.0 or later, using VPN Central Manager does not support preexisting VPN tunnels. In this mode, all tunnels must be created by the FortiManager. VPN tunnels configured prior to enabling VPN central management will be removed.
If FMG 5.6.0 or later, enabling VPN Central Manager will not affect existing VPN tunnels.
So this may not fit your situation. That said, VPN Central Manager can greatly simplify large scale VPN deployments and there is no reason to shy away from it provided it meets your requirements.
I could be wrong, but you'll need to recreate them in the FMG VPN Manager first and then apply the VPNs to the FG in FMG. That's the plan we have anyhow. It made mention of deleting all the VPNs if we turned on the VPN Manager with the FG already added to FMG so the FG was removed from FMG, and then VPN Manager turned on so that VPNs could be recreated.
I wouldn't recommend using the Central VPN Manager tool for IPSec VPNs personally. It's too limited in my opinion, and knowing FMG there are likely some bugs in it since its more of an edge-case feature.
You can still manage your IPSec VPNs directly under the Device itself, which lets you manage each tunnel individually just like you would on a FGT.
You probably need to adjust your Display Settings first:
Device Manager > Tools > Global Display Options
Then under the section for VPN make sure IPSec Phase 1 and 2 are enabled.
Inside Device Manager, you can double-click on your firewall to enter its configuration page (these are the device level settings). You will now see an option for VPN in the grey menu bar.
Note: Even with VPN Central Manager disabled for a given ADOM, you still use it to manage SSLVPN.
> we want to manage VPN on FortiGate but I cannot import the VPN Tunnel on FortiGate to the FortiManager.
Unless you are running FMG 5.6.0 or later, using VPN Central Manager does not support preexisting VPN tunnels. In this mode, all tunnels must be created by the FortiManager. VPN tunnels configured prior to enabling VPN central management will be removed.
If FMG 5.6.0 or later, enabling VPN Central Manager will not affect existing VPN tunnels.
So this may not fit your situation. That said, VPN Central Manager can greatly simplify large scale VPN deployments and there is no reason to shy away from it provided it meets your requirements.
I could be wrong, but you'll need to recreate them in the FMG VPN Manager first and then apply the VPNs to the FG in FMG. That's the plan we have anyhow. It made mention of deleting all the VPNs if we turned on the VPN Manager with the FG already added to FMG so the FG was removed from FMG, and then VPN Manager turned on so that VPNs could be recreated.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.