I'm looking to create a Point-to-Point VPN between a Fortigate 800(version 3.00) and a Fortigate 100D(version 5.00). Is that possible? It appears the option I typically select for VPNs on my 800 are not on the 100D. I believe this is because the 100D is a policy based firewall. They really don't want to invest money into upgrading the 800, even though it's so old. I'm still working on that piece, but in the meantime I'm wondering if this can still be done.
Yes they both are the same. What you might need to do if you want "policy based vpns" is to execute the cfg from the cli or look at the sys global setting for vpns;
config sys global
set gui-policy-based-ipsec en
set gui-vpn en
end
All of these need to be enabled. Bottom line you can do rt-based or policy-based on either model and both sides don't have to agreed. I prefer rt-based and that's recommend method per FTNT
PCNSE
NSE
StrongSwan
Yes, why not? The IPsec standard is a bit older than FortiOS v3.00 and hasn't changed (only expanded e.g. into IKEv2).
I'm not sure if you can create Interface based VPNs on the 800 yet, if you can then do it. Makes life much easier, and helps with debugging. If not, no worry. It's just a FortiOS specific implementation detail and does not affect the IPsec functionality.
BTW, is v3.00 at the latest patch at least, i.e. 3.7.10 build 754?
Very good to know. I figured it would, but when I was greeted by the new options I didn't know what to do. I'll have to read up a little on creating the 100D end. Thanks for confirming
As for the version, we are running 3.00 build 0479,070309. It's been out of support for quite some time, and they won't give me funds to upgrade it. I know it's bad, because that's an old version. They were told that since we are on a managed circuit, the risk isn't as great, so no real need to upgrade right now. Which is total bs, but they listen to that group as if there word is gold. To be honest, I'm just waiting for the moment when we really need it. I know that day won't be pretty *sigh*
That is v3.4.3 of March 2007.
I faintly remember there were issues with IPsec VPN between 3/2007 and 2010 (latest patch v3.7.10). Just try it out, it might work. Just don't use AES256 or anything beyond SHA1...3DES/SHA1 should do, and still is (seen as) safe.
Thanks Ede for the info, I greatly appreciate it! I always get answers and direction when I come here.
Cheers,
You're welcome! the occasional patch on the back will make me happy :)
And good night over there, tomorrow is another day for having fun -
I finally came back to this project, and I thought I had it today, but something weird is going on. I was able to bring up the tunnel, but now I can't bring it down. When I attempt to bring down the tunnel on either the 100D or the 800, it still stays green indicated in the VPN is up. I've refreshed the page too. Very weird. Has anybody experienced this before?
I can't get this working between the 100D and the 800. They each have different settings and options.
What I did with the 100D, was put two ports under a Physical Interface Member for the HSRP setup we have at the colo. My question is, can I do this on a Fortigate 300? The 300 has the same options as the 800, so I would be able to get this up. But I need to make sure the 300 create a Physical Interface Member. I think it was either called something else, or you can't do it on the 300.
Has anybody done this? I know it's old hardware, but hoping somebody can shed some light on this setup. Maybe a diagram of the setup would help?
*edit*
So I was poking around more in the 300, and I think what I need to setup is a zone and add 2 interface ports to the Interface Members.
The colo has us setup with an HSRP setup, and handing us 2 external IP's. We only have one Fortinet, so this is why I'm trying to do the Interface Members configuration.
I'm thinking it might be a good idea to just go on ebay and get a 2nd Fortinet 300, and set them up in a HA. This is the proper way, but was limited on budget, as always.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.