Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jtengono
New Contributor

VPN interface mode with concentrator???

I' ve looked every where in the documentation but have not been able to find if VPN interface mode is able to work with the concentrator. I will greatly appreciate all the information you can provide. John Tengono
9 REPLIES 9
Not applicable

have you checked this ? http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=10230&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=7944557&stateId=0%200%207946300
jtengono
New Contributor

http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=10230&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=7944557&stateId=0%200%207946300
Actually I was asking about the concentrator function in the FORTIGATE.....
ddskier
Contributor

We are using " Interface Mode" and the concentrator now to interconnect several of our locations. Are you having trouble getting it working?

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D

-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
jtengono
New Contributor

Yes, I' m having a heck of a time making it work and can' t find enough information on it. Do you have any docs on it ?? Thanks for your response.
RichardH
New Contributor

My memory may be fuzzy but I thought the concatenator was for Policy Based routes only...
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
-Richard FGT110Cx2 HA A-P - 4.2.11 FGT 80C,60B,50B x 3,FWF50B - 4.2.11 FGT50B - 4.3.3 FGT40C x 2 - 4.3.7 FAMS
abelio

Hi,
ORIGINAL: RichardH My memory may be fuzzy but I thought the concatenator was for Policy Based routes only...
Not at all; doing vpn concentrator with interface or routed based vpns is very straightforward and is documented also. In this scenario, as tunnels are interfaces, you only need to define an ' interface zone' and put all your tunnels inside. Blocking or Allowing intra-zone traffic is your choice if you need AV/IPS...etc for that traffic or not. In former case you' ll need firewall policy from zone to zone itself to apply protection profiles. regards.,

regards




/ Abel

regards / Abel
jtengono
New Contributor

Thanks Abel, If you happen to have a link to the docs, I would greatly appreciate it. Also are you using static routing or dynamic routing for your implementations? Regards.
abelio

Do a search for " concentrator route based" within http://kb.fortinet.com regards,

regards




/ Abel

regards / Abel
PauloP
New Contributor III

Have you ever read: docs.fortinet.com/fgt/handbook/fortigate-ipsec-40-mr1.pdf Everything is deeply explained in this doc. (There are other versions to earlier versions of FortiOS). Regards, Paulo
Labels
Top Kudoed Authors