Це відео не доступне.
Перепрошуємо.

Fortinet: How to Setup a Route-Based IPSec VPN Tunnel on a FortiGate Firewall

Поділитися
Вставка
  • Опубліковано 1 кві 2020
  • When it comes to remote work, VPN connections are a must. But they come in multiple shapes and sizes.
    Join Firewalls.com Network Engineer Matt as he shows you how to setup a route-based IPSec VPN tunnel on a Fortinet FortiGate firewall to offer a secure work from home option on your network.
    Learn more about Fortinet: www.firewalls....
    And get a primer on FortiClient Endpoint Protection's offerings for remote work www.firewalls....

КОМЕНТАРІ • 64

  • @firewallsDotCom
    @firewallsDotCom  2 роки тому

    For assistance please visit our website for support www.firewalls.com/wd/firewall-configuration/

  • @AaronMichaelLong
    @AaronMichaelLong 2 місяці тому +3

    This is not a route-based VPN, this is a policy-based VPN configuration. The fact that you're identifying specific phase 2 proxy-IDs/selectors is what makes it policy-based.

  • @JR34MZ
    @JR34MZ 4 роки тому +9

    This helped me greatly as my team is very new to Fortigate. I genuinely appreciate your time on this one!

    • @firewallsDotCom
      @firewallsDotCom  4 роки тому +1

      Glad we could help! Thanks very much for the feedback, and for watching!

  • @yushis
    @yushis 2 роки тому +2

    Awesome video. I'm coming from Watchguard so this is a new experience for me. Straight and to the point.

  • @richhughsam6464
    @richhughsam6464 3 роки тому +3

    This is a very good video, put together clear and concise. Well done!

    • @firewallsDotCom
      @firewallsDotCom  3 роки тому

      Thanks very much for the feedback, and for watching!

  • @lostinvasion
    @lostinvasion 6 місяців тому +1

    this helped me out a lot, thanks for sharing!

  • @LakshyaCharms
    @LakshyaCharms 2 роки тому +7

    Hello, you said it's route based and but added local and remote subnets in interested traffic. Can you clarify?

  • @adnaansiddiqi8772
    @adnaansiddiqi8772 3 роки тому +9

    Shouldn't route-based VPN be any network through tunnels and then control through the routing protocol which networks to allow?

  • @_eurosign
    @_eurosign 2 роки тому +2

    Couldn’t be simpler than this. Many thanks.

    • @firewallsDotCom
      @firewallsDotCom  2 роки тому +1

      Thanks for sharing that feedback, and appreciate you watching!

  • @capcata
    @capcata 4 роки тому +27

    This is NOT A routed VPN. This is a normal vpn.

  • @teknolojigundemi
    @teknolojigundemi Місяць тому

    Good explanation.Every software update changes behaviour. I dont know it is similar today. There is a Tunnel Interface under WAN physical. What should its settings be like.

  • @conorpodonoghue
    @conorpodonoghue Рік тому

    Thanks for this. What would be really helpful is a network diagram.

  • @doctor.networks
    @doctor.networks 2 роки тому +4

    Great Video. Just one thing, This is a POLICY Based VPN not a ROUTE based VPN, a Route Based VPN is something like a GRE over IPsec or VTI tunnel. Something on which routing protocols can work.

    • @cheong4141
      @cheong4141 Рік тому

      r u using Cisco concept to estimate Fortigate? anyway, pls view it as vti.

  • @RozzClips
    @RozzClips 10 днів тому

    Hi what if there's 4 IP address ranges behind the sonic wall? How can add multiple ranges?

  • @MohammedAli-pf2oc
    @MohammedAli-pf2oc 2 роки тому

    Amazing, just one more question on 3:20 what u did again exactly and why??

  • @Wael_Fakhri
    @Wael_Fakhri Рік тому

    very good video, Well done!

  • @juancz4886
    @juancz4886 10 місяців тому

    Thanks Matt!

  • @TWInter-fb6wo
    @TWInter-fb6wo 3 роки тому

    I Can ' Remote Router Site B When Connect With forticlient ipsec But Remote Site A Can Be Used

  • @ambadaschankhore2714
    @ambadaschankhore2714 4 роки тому

    Great Video..Thank you for sharing good knowledge.

  • @Spegarinos
    @Spegarinos 3 роки тому +1

    If we have a profile based firewall what is the difference in the settings ?

  • @georgemandilas896
    @georgemandilas896 3 роки тому

    Hi
    locally i can connect but from my job it can not connect

  • @adetutuogunsowo7939
    @adetutuogunsowo7939 3 роки тому +1

    Can one implement a VPN tunnel on the LAN, two machines on different switches and VLANs but where inter-vlan routing happens at the layer 3 Fortinet FW? Thanks for your response

  • @Nubsauce
    @Nubsauce 2 роки тому

    how do you get the actual site to site tunnel to work and have the central fortigate share its internet with the remote fortigate?

  • @romandavydov8684
    @romandavydov8684 2 роки тому

    Thank you for the tutorial. I have a question.
    My ISP is using L2TP IPsec for connection to internet.
    Curently I am using a zyxel router to connect to ISP internet. my fortigate is connected to the router now.
    I would like to connect my fortigate to the ISP directly. Cable from ISP directly to the fortigate.
    How can I configyre my wan connection as L2TP IPsec to connect to the internet?
    Please give me a piece of advice.
    Thank you

  • @the3cobblers683
    @the3cobblers683 3 роки тому

    Thought we should build a full 0.0.0.0/0 subnet both side for route based VPN?

  • @svbakulin
    @svbakulin 4 місяці тому +1

    This is not route based VPN, it is an old school policy VPN.

  • @princepolitely7559
    @princepolitely7559 2 роки тому

    Hello,
    I am trying to configure IPsec VPN with Fortigate 300e firewall but couldn't succeed.
    Can anyone help me in configuring the VPN from NGAF AF-1000 to Fortigate 300e?
    also on 300e. i don't have ipv4 policy option. (Policy & Objects -> ipv4 policy)

  • @hoangtruong7166
    @hoangtruong7166 2 роки тому

    What is head office and branch office have several VLAN

  • @unknownwolf4046
    @unknownwolf4046 3 роки тому

    I have 4G Router bec mx210np R17 I setup Ipsec but wont connect

  • @stnkubinka
    @stnkubinka 2 роки тому

    If I have two peers at remote device (two ISP - main and reserve), how can I set second peer on Phase 1 on FortiGate?

  • @gre1677
    @gre1677 2 роки тому +2

    I think this is for policy based vpn tunnel not a route based. anyway thank you for your videos :)

  • @rockinron5113
    @rockinron5113 Рік тому

    Nice one! Cheers

  • @xtwist3779
    @xtwist3779 Рік тому

    give me link to this fortigate soft

  • @schampion3
    @schampion3 3 роки тому

    It would be helpful to post the corollary of setting up a Sonicwall TZxxx to work with a route based Fortigate IPSEC VPN Tunnel.

    • @arunparthan
      @arunparthan Рік тому

      ua-cam.com/video/nEEA09fBZ1Q/v-deo.html

  • @amarabaz6147
    @amarabaz6147 2 роки тому +1

    Hello there. One question can I use it like this to make a tunnel towards NordVPN. I have a FortiGate 100E ?

    • @firewallsDotCom
      @firewallsDotCom  2 роки тому

      IPsec is an open standard and should work with any vendor that supports it. Thanks for your comment and be sure to subscribe for new content.

  • @zizolibob
    @zizolibob 2 роки тому

    Very helpful!
    Can you please explain us why you disabled NAT on both policy rules?

    • @mustafamzale6597
      @mustafamzale6597 Рік тому +1

      NAT is optional, it depend what is the remote subnet is. If the remote subnet is different with your subnet you can disable so real IP is reaching remote site. But it is advised to NAT and use public IP incase you are integrating with multiple sites. it will avoid LAN overlap

  • @MrKarlbarat
    @MrKarlbarat 4 роки тому

    thanks for the help, maybe later you can make a video how to setup a site to site vpn with aws

  • @chuckjamm
    @chuckjamm 3 роки тому

    have you setup a route based vpn between fortigate and asa?

  • @thomasjoseph9609
    @thomasjoseph9609 2 роки тому

    it is help me alot

  • @m0rphe0-8
    @m0rphe0-8 2 роки тому +1

    why is needed static route ?

    • @firewallsDotCom
      @firewallsDotCom  2 роки тому

      You need to have a static route so that the firewall knows who to send what traffic to. You can use a static route or dynamic routing protocols such as OSPF as well. Thanks for your comment and be sure to subscribe for new content.

  • @pavelky8833
    @pavelky8833 3 роки тому

    Thanks dude !!!

  • @v1c81
    @v1c81 4 роки тому

    I want a branch to make a dual vpn to my hq with wan1 and wan2 in sdwan. Do you have a video for that. Keeps saying duplicate exists.

  • @MadalinVladescu
    @MadalinVladescu 3 роки тому

    can you show us how to route all internet traffic through the Fortigate? thank for you videos

    • @cr7fanatics792
      @cr7fanatics792 3 роки тому

      Disable split tunnel in ipsec.. Then all the internet traffic will be routed through fortigate.

  • @FRZ2012
    @FRZ2012 3 роки тому

    Many thanks

    • @firewallsDotCom
      @firewallsDotCom  3 роки тому

      Many thanks to you too for watching and commenting!

  • @chunkityeong5225
    @chunkityeong5225 4 роки тому

    Will it work if we leave the local and remote address as 0.0.0.0(any)? or we must specify? thanks.

    • @evexs98
      @evexs98 4 роки тому

      Use administrative distance, be cause you need 0.0.0.0/0 to use internet.

  • @cason4468
    @cason4468 2 роки тому

    it was amazing, but it could be better with a less tired voice

  • @bschelst
    @bschelst 3 роки тому

    That's policy based tunnel,not route based tunnel

  • @iphelper1574
    @iphelper1574 3 місяці тому +1

    Misguided tutorial. Should have been named as policy-based VPN