Fortinet black logo

Cookbook

Configuring firewall policies on HQ

Copy Link
Copy Doc ID a4a06ec3-12a7-11e9-b86b-00505692583a:754815
Download PDF

Configuring firewall policies on HQ

  1. To create firewall policies on HQ, go to Policy & Objects > IPv4 Policies and select Create New.
  2. Enter From-HQ-to-Branch for the Name, the LAN-side interface on HQ for Incoming Interface (in the example, internal), and the VPN tunnel interface for Outgoing Interface (in the example, VPN-to-Branch).

  3. For the Source, select HQ-original, for the Destination select Branch-new, and for the Service select ALL.
  4. Finally, enable NAT, select Use Dynamic IP Pool, and select the HQ-new IP Pool.
  5. Repeat the process to create an additional new IPv4 Policy.
  6. Enter From-Branch-to-HQ for the Name, the VPN interface for Incoming Interface (in the example, VPN-to-Branch), and the LAN-side interface for Outgoing Interface (in the example, internal).

  7. For the Source, select Branch-new, for the Destination select HQ-new-to-original (the Virtual IP object you created in the "Configuring static routes on HQ" section), and for the Service select ALL.
  8. Note for this policy, you do not need to enable NAT.

Configuring firewall policies on HQ

  1. To create firewall policies on HQ, go to Policy & Objects > IPv4 Policies and select Create New.
  2. Enter From-HQ-to-Branch for the Name, the LAN-side interface on HQ for Incoming Interface (in the example, internal), and the VPN tunnel interface for Outgoing Interface (in the example, VPN-to-Branch).

  3. For the Source, select HQ-original, for the Destination select Branch-new, and for the Service select ALL.
  4. Finally, enable NAT, select Use Dynamic IP Pool, and select the HQ-new IP Pool.
  5. Repeat the process to create an additional new IPv4 Policy.
  6. Enter From-Branch-to-HQ for the Name, the VPN interface for Incoming Interface (in the example, VPN-to-Branch), and the LAN-side interface for Outgoing Interface (in the example, internal).

  7. For the Source, select Branch-new, for the Destination select HQ-new-to-original (the Virtual IP object you created in the "Configuring static routes on HQ" section), and for the Service select ALL.
  8. Note for this policy, you do not need to enable NAT.