Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ZiPPy
New Contributor

P2P VPN between old and new

I'm looking to create a Point-to-Point VPN between a Fortigate 800(version 3.00) and a Fortigate 100D(version 5.00).  Is that possible?  It appears the option I typically select for VPNs on my 800 are not on the 100D.  I believe this is because the 100D is a policy based firewall.  They really don't want to invest money into upgrading the 800, even though it's so old.  I'm still working on that piece, but in the meantime I'm wondering if this can still be done.

8 REPLIES 8
emnoc
Esteemed Contributor III

Yes they both are the same. What you might need to do if you want "policy based vpns" is to execute the cfg from the cli or look at the sys global setting for  vpns;

 

config sys global

   set gui-policy-based-ipsec  en

  set gui-vpn en

end

 

All of these need to be enabled. Bottom line you can do rt-based or policy-based on either model and both sides don't have to agreed. I prefer rt-based and that's recommend method per FTNT

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
SuperUser
SuperUser

Yes, why not? The IPsec standard is a bit older than FortiOS v3.00 and hasn't changed (only expanded e.g. into IKEv2).

I'm not sure if you can create Interface based VPNs on the 800 yet, if you can then do it. Makes life much easier, and helps with debugging. If not, no worry. It's just a FortiOS specific implementation detail and does not affect the IPsec functionality.

BTW, is v3.00 at the latest patch at least, i.e. 3.7.10 build 754?

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
ZiPPy
New Contributor

Very good to know.  I figured it would, but when I was greeted by the new options I didn't know what to do.  I'll have to read up a little on creating the 100D end.  Thanks for confirming

 

As for the version, we are running 3.00 build 0479,070309.  It's been out of support for quite some time, and they won't give me funds to upgrade it.  I know it's bad, because that's an old version.  They were told that since we are on a managed circuit, the risk isn't as great, so no real need to upgrade right now.  Which is total bs, but they listen to that group as if there word is gold.  To be honest, I'm just waiting for the moment when we really need it.  I know that day won't be pretty *sigh*

 

 

ede_pfau
SuperUser
SuperUser

That is v3.4.3 of March 2007.

I faintly remember there were issues with IPsec VPN between 3/2007 and 2010 (latest patch v3.7.10). Just try it out, it might work. Just don't use AES256 or anything beyond SHA1...3DES/SHA1 should do, and still is (seen as) safe.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
ZiPPy
New Contributor

Thanks Ede for the info, I greatly appreciate it!  I always get answers and direction when I come here.

Cheers,

ede_pfau
SuperUser
SuperUser

You're welcome! the occasional patch on the back will make me happy :)

 

And good night over there, tomorrow is another day for having fun -

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
ZiPPy
New Contributor

I finally came back to this project, and I thought I had it today, but something weird is going on.  I was able to bring up the tunnel, but now I can't bring it down.  When I attempt to bring down the tunnel on either the 100D or the 800, it still stays green indicated in the VPN is up.  I've refreshed the page too.  Very weird.  Has anybody experienced this before? 

ZiPPy
New Contributor

I can't get this working between the 100D and the 800.  They each have different settings and options.

 

What I did with the 100D, was put two ports under a Physical Interface Member for the HSRP setup we have at the colo.  My question is, can I do this on a Fortigate 300?  The 300 has the same options as the 800, so I would be able to get this up.  But I need to make sure the 300 create a Physical Interface Member.  I think it was either called something else, or you can't do it on the 300.

 

Has anybody done this?  I know it's old hardware, but hoping somebody can shed some light on this setup.  Maybe a diagram of the setup would help?

 

*edit*

So I was poking around more in the 300, and I think what I need to setup is a zone and add 2 interface ports to the Interface Members.  

The colo has us setup with an HSRP setup, and handing us 2 external IP's.  We only have one Fortinet, so this is why I'm trying to do the Interface Members configuration.

I'm thinking it might be a good idea to just go on ebay and get a 2nd Fortinet 300, and set them up in a HA. This is the proper way, but was limited on budget, as always.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors