- On Branch, go to VPN > IPsec Wizard, and create a new tunnel.
In the VPN Setup section, set Template Type to Site to Site.
Set Remote Device Type to FortiGate.
Set NAT Configuration to No NAT between sites.
- In the Authentication section, set IP Address to the public IP address of the HQ FortiGate (in this example, 172.25.176.62).
After you enter the IP address, an interface is assigned as the Outgoing Interface. If you want to use a different interface, select it from the dropdown menu.
Set the secure Pre-shared Key that was used for the VPN on HQ.
- In the Policy & Routing section, set Local Interface to lan. The local subnet is added automatically.
Set Remote Subnets to the HQ network’s subnet (in this example, 192.168.65.0/24).
Set Internet Access to None.
- Review the configuration summary that shows the interfaces, firewall addresses, routes, and policies.
- To bring up the VPN tunnel, go to Monitor > IPsec Monitor. Right-click the Status and select Bring Up.
You might need to refresh the page before the Status shows Up.