- On Branch, go to VPN > IPsec Wizard.
Select the Site to Site template and select Next.
- In the Authentication section, set IP Address to HQ's Internet-facing IP (in this example, 172.31.1.64).
After you enter the gateway, an interface is assigned as the Outgoing Interface.
Set the same Pre-shared Key that was used for HQ’s VPN.
- In the Policy & Routing section, set the Local Interface. The Local Subnets is added automatically.
Set Remote Subnets to HQ's local subnet (in this example, 10.1.1.0/24).
- Review the configuration summary.
- On either FortiGate, go to Monitor > IPsec Monitor to verify the status of the VPN tunnel. Right-click its Status and select Bring Up.
Check that the multicast server behind HQ can ping the client at Branch. To generate traffic to test the connection, ping Branch's internal interface from HQ’s internal network.