Adding gateways to VPN communities
After you create the VPN communities named OL_INET and OL_MPLS, the next step is to add managed gateways to the communities.
Add the following gateways to each VPN community:
- branch1_fgt
- branch2_fgt
- dc1_fgt
- dc2_fgt
Add the hub devices one by one to each community. Each hub device has different IP ranges defined for the IKE Config Mode (see the table below).
Use the following parameters for each hub device:
Parameter |
Value |
---|---|
Protected Subnet |
All |
Role |
Hub |
Default VPN Interface |
Underlay port port1 for OL_INET and port4 for OL_MPLS |
Routing |
Manual |
Peer Type |
Accept any peer type |
IKE Config Mode |
ON Hubs will assign tunnel IP addresses to Spokes |
IPv4 Start/End/Mask |
10.200.<overlay-id>.1-9/24 |
Add Route |
OFF No static route injection. Routing will be handled by BGP. |
net-device |
OFF |
tunnel-search |
nexthop |
Use the following parameters for each spoke device:
Parameter |
Value |
---|---|
Protected Subnet |
All |
Role |
Spoke |
Default VPN Interface |
Underlay port port1 for OL_INET and port4 for OL_MPLS |
Routing |
Manual |
IKE Config Mode |
ON Hubs will assign tunnel IP addresses to Spokes |
Add Route |
OFF No static route injection. Routing will be handled by BGP. |
net-device |
OFF |
To add a gateway to the OL_INET VPN community from the GUI:
- Go to VPN Manager > IPsec VPN.
- In the tree menu, double-click OL_INET to open it for editing.
- In the toolbar, click Create New > Managed Gateway.
The VPN Gateway Setup Wizard - OL_INET is displayed.
- On the Protected Network tab, set the following options, and click Next:
- Click Protected Subnet, select all, and click OK.
- On the Device tab, set the following options, and click Next.
- Set the Role field to Spoke.
- From the Device list, select a branch FortiGate.
- On the Default VPN Interface tab, set the following options, and click Next.
- In the Default VPN Interface list, select an underlay port.
- On the Local Gateway tab, click Next to accept the defaults.
- On the Advanced tab, set the following options, and click OK:
- Beside Routing, select Manual (via Device Manager).
- Beside Enable IKE Configuration Method ("mode config"), toggle ON.
- Beside Add Route, toggle OFF.
- Under Advanced Options, set net-device to OFF.
The branch is added to the OL_INET VPN community.
Similarly, add the other branch to the OL_INET VPN community.
To add a hub to the OL_INET VPN community from the GUI:
- Go to VPN Manager > IPsec VPN.
- In the tree menu, click OL_INET.
- In the toolbar, click Create New > Managed Gateway.
The VPN Gateway Setup Wizard - OL_INET is displayed.
- On the Protected Network tab, set the following options, and click Next:
- Click Protected Subnet, select all, and click OK.
- On the Device tab, set the following options, and click Next.
- Set the Role field to Hub.
- From the Device list, select a hub FortiGate.
- On the Default VPN Interface tab, set the following options, and click Next.
- In the Default VPN Interface list, select an underlay port.
- On the Local Gateway tab, click Next to accept the defaults.
- On the Advanced tab, set the following options, and click OK:
- Beside Routing, select Manual (via Device Manager).
- Beside Peer Type, select Accept any peer ID.
- Beside Enable IKE Configuration Method ("mode config"), toggle ON.
- In the IPv4 Start IP box, type the start of the IP range.
- In the IPv4 End IP box, type the end of the IP range.
- Beside Add Route, toggle OFF.
- Under Advanced Options, set net-device to OFF.
- Set tunnel-search to nexthop.
The hub is added to the OL_INET VPN community.
Similarly, add the other hub to the OL_INET VPN community.
Once you have added both the branches and both hubs to the OL_INET VPN community, do the same for OL_MPLS VPN community as well.
Once you have configured the VPN Manager, your configuration should appear as follows: