Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
marcosta87
New Contributor

VPN Site-to-Site FortGate 60E and Windows Server 2016 (directly)

Hello, 

 I need to establish a permanent VPN connection between my local network (FortiGate 60E for example) and a remote windows server 2016 (to share files between my local network and file server). I want to allow my users inside the local network access to the remote server, automatically, over s2s VPN connection. Is it possible?  

My end users use MAC OS computers, and outside LAN, they using a VPN L2TP/IPSec connection, the same protocol in windows server side. 

 

Thank you! 

2 REPLIES 2
ede_pfau
SuperUser
SuperUser

hi,

first thought: bad idea to expose a universal purpose OS to the internet. Very bad idea.

You could use any used old FGT or a new FG-30E without UTM, just with FortiCare contract, as a secure VPN gateway. As an added benefit, it would make the VPN function completely independent of the server's OS hicckups and patches.

 

OK, back to your question:

the desktop models (smaller than FG-100x) offer L2TP client functionality. You configure it in the CLI only. It can use IPsec in phase2 for encryption. This is not as secure as a real IPsec VPN but people don't care too much.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
sw2090
SuperUser
SuperUser

Probably the clients could use FortiClient to set up a s2s vpn to your FGT and then you just need some policy to allow access from the vpn subnet to your server.

This is what we do here with our Laptops when we are not at office.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors