Fortinet white logo
Fortinet white logo

Cookbook

IPsec VPN wizard hub-and-spoke ADVPN support

IPsec VPN wizard hub-and-spoke ADVPN support

The IPsec Wizard can be used to create hub-and-spoke VPNs, with ADVPN enabled to establish tunnels between spokes.

The following example shows the steps in the wizard for configuring a hub and a spoke.

To configure the hub:
  1. On the hub FortiGate, go to VPN > IPsec Wizard.

  2. Enter a name, set the Template Type to Hub-and-Spoke, and set the Role to Hub.
  3. Click Next.

  4. Select the Incoming Interface and configure the Authentication method.
  5. Click Next.

  6. Set the IP address and Remote IP/netmask.
  7. Click Next.

  8. Configure the Local identifier, Local interface, and Local subnets, then configure the tunnel IP addresses and identifiers for the spokes.
  9. Click Create.

  10. Review the summary to ensure that everything looks as expected.
  11. Copy the spokes' easy configuration keys to a temporary location for use when configuring the spokes.
To configure a spoke:
  1. On the spoke FortiGate, go to VPN > IPsec Wizard.

  2. Enter a name, set the Template Type to Hub-and-Spoke, set the Role to Spoke, and paste in the requisite Easy configuration key that you saved when configuring the hub.
  3. Click Next.

  4. Set the Remote IP address, select the Incoming Interface, and configure the Authentication method.
  5. Click Next.

  6. Set the IP address and Remote IP/netmask.
  7. Click Next.

  8. Configure the Local identifier, Local interface, and Local subnets, then configure the IP address and identifier of the hub FortiGate.
  9. Click Create.

  10. Review the summary to ensure that everything looks as expected.
To check the ADVPN shortcut with the IPsec monitor:
  1. On either the hub or spoke FortiGate, go to Monitor > IPsec Monitor.

IPsec VPN wizard hub-and-spoke ADVPN support

IPsec VPN wizard hub-and-spoke ADVPN support

The IPsec Wizard can be used to create hub-and-spoke VPNs, with ADVPN enabled to establish tunnels between spokes.

The following example shows the steps in the wizard for configuring a hub and a spoke.

To configure the hub:
  1. On the hub FortiGate, go to VPN > IPsec Wizard.

  2. Enter a name, set the Template Type to Hub-and-Spoke, and set the Role to Hub.
  3. Click Next.

  4. Select the Incoming Interface and configure the Authentication method.
  5. Click Next.

  6. Set the IP address and Remote IP/netmask.
  7. Click Next.

  8. Configure the Local identifier, Local interface, and Local subnets, then configure the tunnel IP addresses and identifiers for the spokes.
  9. Click Create.

  10. Review the summary to ensure that everything looks as expected.
  11. Copy the spokes' easy configuration keys to a temporary location for use when configuring the spokes.
To configure a spoke:
  1. On the spoke FortiGate, go to VPN > IPsec Wizard.

  2. Enter a name, set the Template Type to Hub-and-Spoke, set the Role to Spoke, and paste in the requisite Easy configuration key that you saved when configuring the hub.
  3. Click Next.

  4. Set the Remote IP address, select the Incoming Interface, and configure the Authentication method.
  5. Click Next.

  6. Set the IP address and Remote IP/netmask.
  7. Click Next.

  8. Configure the Local identifier, Local interface, and Local subnets, then configure the IP address and identifier of the hub FortiGate.
  9. Click Create.

  10. Review the summary to ensure that everything looks as expected.
To check the ADVPN shortcut with the IPsec monitor:
  1. On either the hub or spoke FortiGate, go to Monitor > IPsec Monitor.