Fortinet white logo
Fortinet white logo

Cookbook

Configuring firewall policies on Branch

Configuring firewall policies on Branch

  1. To create firewall policies on Branch, navigate to Policy & Objects > IPv4 Policies and select Create New.
  2. Enter From-Branch-to-HQ for the Name, the LAN-side interface on Branch for Incoming Interface (in the example, lan), and the VPN tunnel interface for Outgoing Interface (in the example, VPN-to-HQ).

  3. For the Source, select Branch-original, for the Destination select HQ-new, and for the Service select ALL.
  4. Finally, enable NAT, select Use Dynamic IP Pool, and select the Branch-new IP Pool.
  5. Repeat the process to create an additional new IPv4 Policy.
  6. Enter From-HQ-to-Branch for the Name, the VPN interface for Incoming Interface (in the example, VPN-to-HQ), and the LAN-side interface for Outgoing Interface (in the example, lan).

  7. For the Source, select HQ-new, for the Destination select Branch-new-to-original (the Virtual IP object you created in the "Configuring address objects, Virtual IPs, and IP Pools on Branch" section), and for the Service select ALL.
  8. Note for this policy, you do not need to enable NAT.

Configuring firewall policies on Branch

Configuring firewall policies on Branch

  1. To create firewall policies on Branch, navigate to Policy & Objects > IPv4 Policies and select Create New.
  2. Enter From-Branch-to-HQ for the Name, the LAN-side interface on Branch for Incoming Interface (in the example, lan), and the VPN tunnel interface for Outgoing Interface (in the example, VPN-to-HQ).

  3. For the Source, select Branch-original, for the Destination select HQ-new, and for the Service select ALL.
  4. Finally, enable NAT, select Use Dynamic IP Pool, and select the Branch-new IP Pool.
  5. Repeat the process to create an additional new IPv4 Policy.
  6. Enter From-HQ-to-Branch for the Name, the VPN interface for Incoming Interface (in the example, VPN-to-HQ), and the LAN-side interface for Outgoing Interface (in the example, lan).

  7. For the Source, select HQ-new, for the Destination select Branch-new-to-original (the Virtual IP object you created in the "Configuring address objects, Virtual IPs, and IP Pools on Branch" section), and for the Service select ALL.
  8. Note for this policy, you do not need to enable NAT.