Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Need2Know
New Contributor II

Site to Site VPN Fortigate 40F to Azure

Device : Fortigate 40F

Firmware :v7.0.12 build0523 (Mature)

 

I am following this article to configure site to site VPN :

 

https://newhelptech.wordpress.com/2022/01/01/step-by-step-how-to-configure-site-to-site-vpn-microsof...

 

 

2023-08-07_12-25-00.jpg

 

Logs.jpg

I am not sure how to setup parameters for phase 1 and phase 2 tunnel and how do I configure Phase 2 tunnel since I cant find any options in firewall console.

20 REPLIES 20
akushwaha
Staff
Staff

Hi,
As I understand you're trying to configure IPSEC site to site VPN between FortiGate and Microsoft Azure for that please refer to the below document:
https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/255100/ipsec-vpn-to-azure-wi...

If the VPN is not coming up, please share me the output of below commands:

# diagnose vpn tunnel list < tunnel name >
# diagnose vpn ike gateway list < tunnel name >
# diagnose vpn ike status < tunnel name >
# diagnose vpn ike config list < tunnel name >
# diagnose vpn ike status detailed < tunnel name >
# diag vpn ike log-filter dst-addr4 <IP>
# diag debug console timestamp enable
# diag de app ike -1
# diag de en

Let the debugs run for 2-3 minutes and then stop debugging by;
# diagnose debug disable
# diagnose debug reset


Best Regards,
Abhimanyu

Need2Know
New Contributor II

I don't see the options highlighted in bold. Please see below screenshots for your reference.
 
To configure the FortiGate tunnel:
  1. In the FortiGate, go to VPN > IP Wizard.
  2. Enter a Name for the tunnel, click Custom, and then click Next.
  3. Configure the Network settings.
    1. For Remote Gateway, select Static IP Address and enter the IP address provided by Azure.
    2. For Interface, select wan1.
    3. For NAT Traversal, select Disable,
    4. For Dead Peer Detection, select On Idle.
    5. In the Authentication section, select
  4. Configure the Authentication settings.
    1. For Method, select Pre-shared Key and enter the Pre-shared Key.
    2. For IKE, select 2.
  5. Configure the Phase 1 Proposal settings.
    1. Set the Encryption and Authentication combination to the three supported encryption algorithm combinations accepted by Azure.
      • AES256 and SHA1
      • 3DES and SHA1
      • AES256 and SHA256
    2. For Diffie-Hellman Groups, select 2.
    3. Set Key Lifetime (seconds) to 28800.
  6. In Phase 2 Selectors, expand the Advanced section to configure the Phase 2 Proposal settings.
    1. Set the Encryption and Authentication combinations:

      • AES256 and SHA1
      • 3DES and SHA1
      • AES256 and SHA256
    2. Uncheck Enable Perfect Forward Secrecy (PFS).
    3. Set Key Lifetime (seconds) to 27000.
  7. Click OK.

0002.jpg0003.jpg0000.jpg0001.jpg

pgautam
Staff
Staff

Hi @Need2Know 

 

In place of the manual try to configure the tunnel using the IPSECVPN wizard to avoid the chance of missing any configuration of phase 1 and phase 2.

 

https://docs.fortinet.com/document/fortigate/7.0.12/administration-guide/913287/basic-site-to-site-v...

 

Regards

Priyanka


- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

 

Need2Know
New Contributor II

@pgautam Please note that this is production site. let me know if this will not effect exiting state of the firewall

pgautam

Hi @Need2Know 

 

Creating a new site to the tunnel will not impact other internet traffic, however for the best practice it's recommended you make changes in the off-production time for the new configuration testing.

 

Regards

Priyanka


- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

 

 

Need2Know
New Contributor II

1.jpg

Need2Know
New Contributor II

IP addresses on Azure

Need2Know
New Contributor II

Just wanted to confirm if I need to use default subnet or gateway subnet for  S2SVPN_remote_subnet_1 on Fortinet firewall.

Need2Know
New Contributor II

5.jpg2.jpg3.jpg4.jpg

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors