Configuring a full mesh VPN topology within a VPN console
This is an example on how to configure a simple full mesh VPN with:
- Three FortiGate (FGT) devices
- A pre-shared key for authentication
- An auto-up tunnel setting
- Static routes
To configure a full mesh VPN topology within a VPN console:
- Add FortiGate devices and map all interfaces:
- Go to Device Manager. Add three FortiGate devices by clicking Add Device. Follow the wizard to add each device.
- Go to Policy & Objects > Policy Packages and define the Zone interfaces.
- Go to Device Manager and select a device.
- Go to System > Interface and map the interfaces to the Zone interfaces.
- Create firewall addresses for protected subnets:
- Go to Policy & Objects > Firewall Objects > Address to manage the firewall addresses.
- VPNs only support firewall addresses with the type set to subnet (IP/Netmask). The firewall addresses will be used as protected subnets to generate static routes among the FortiGate devices.
- Create a VPN community:
- Go to VPN Manager > IPsec VPN Communities > Create New.
- Set the VPN Topology type to Site to Site.
- Define the Authentication method with a Pre-shared Key.
- Specify the encryption and hash methods.
- After defining the authentication methods and encryption properties, click Next.
- Configure the VPN Phase 1 and Phase 2 settings.
- For the IPSec Phase 2 setting, set the tunnel to Auto-Negotiate.
VPN configuration summary:
- Add a VPN gateway:
- Go to VPN Manager > IPsec VPN Communities and select your VPN community.
- Right-click the community and select Add Managed Gateway.
- Add a Protected Network. There can be more than one protected networks.
- Select a Device.
- Select a Default VPN Interface. The default VPN interface should have a valid IP and be mapped.
- Optionally, specify the Local Gateway. This option can be left blank in most cases.
- Go to Routing and select Automatic to generate static routes.
- If Manual is selected, go to the Device Manager to set the IP on the relevant IPSec interfaces and define the routings manually.
VPN gateway configuration settings summary:
- Create firewall policies:
- Go to Policy & Objects > Policy Package to create policies among the default VPN zones and protected-subnet interfaces.
- Use the Install On option to restrict policies applied on specific FortiGate devices.
- Remember to create policies for bi-directional traffic.
For further FortiManager information, refer to the FortiManager Administration Guide available on the Fortinet Document Library.