Fortinet white logo
Fortinet white logo
7.4.4

Tunneling protocol and encapsulation

Tunneling protocol and encapsulation

SSL VPN uses the TLS protocol for tunneling.

However Fortinet’s IPsec VPN offers the following options for tunneling and encapsulation:

  • Native ESP

  • UDP encapsulation

  • TCP encapsulation with Fortinet proprietary extension to allow inline ASIC offloading

  • TCP encapsulation using RFC 8229

When ESP is used without encapsulation, it connects directly over IP Protocol 50. When ESP is encapsulated within UDP, it uses UDP/500 and UDP/4500 for NAT traversal, which are the options for dial-up IPsec VPN.

In IPsec site-to-site tunnels, the UDP port can be customized. See Configurable IKE port.

In IPsec site-to-site tunnels using IKEv2, the TCP port can also be customized. See Encapsulate ESP packets within TCP headers.

Tunneling protocol and encapsulation

Tunneling protocol and encapsulation

SSL VPN uses the TLS protocol for tunneling.

However Fortinet’s IPsec VPN offers the following options for tunneling and encapsulation:

  • Native ESP

  • UDP encapsulation

  • TCP encapsulation with Fortinet proprietary extension to allow inline ASIC offloading

  • TCP encapsulation using RFC 8229

When ESP is used without encapsulation, it connects directly over IP Protocol 50. When ESP is encapsulated within UDP, it uses UDP/500 and UDP/4500 for NAT traversal, which are the options for dial-up IPsec VPN.

In IPsec site-to-site tunnels, the UDP port can be customized. See Configurable IKE port.

In IPsec site-to-site tunnels using IKEv2, the TCP port can also be customized. See Encapsulate ESP packets within TCP headers.