Using redundant OSPF routing over IPsec VPN
217
con
fi
rm that the secondary tunnel will be
used automatically to maintain a secure
connection.
Verify the IPsec VPN tunnel statuses on
FortiGate 1 and FortiGate 2. Both FortiGates
should show that primary tunnel is DOWN
and secondary tunnel is UP.
Go to
VPN > Monitor > IPsec Monitor
to
verify the status.
Verify the routing table on FortiGate 1 and
FortiGate 2.
The secondary OSPF route (with cost = 100)
appears on both FortiGate units.
Go to
Router > Monitor > Routing
Monitor
. Type OSPF for the
Type
and
select
Apply Filter
to verify OSPF route.
Verify that traf
fi
c
fl
ows via the secondary
tunnel.
From a PC1 set to IP:10.20.1.100 behind
FortiGate 1, run a tracert to a PC2 set to
IP:10.21.1.100 behind FortiGate 2 and
vice versa. From PC1, you should see that
the traf
fi
c goes through 10.2.1.2 which is
the secondary tunnel interface IP set on
FortiGate 2.
From PC2, you should see the traf
fi
c goes
through 10.2.1.1 which is the secondary
tunnel interface IP set on FortiGate 1.
THE FOR
TIGA
TE COOKBOOK
Summary of Contents for FortiGate 1U
Page 1: ...FortiOS 5 0 4 1U Models ...
Page 3: ......
Page 4: ...2 ...
Page 5: ...3 QUICKSTART GUIDE FortiGate 1U QuickStart Guide ...
Page 14: ......
Page 15: ...The FortiGate Cookbook Recipes for Success with your FortiGate THE FORTIGATE COOKBOOK ...
Page 16: ......
Page 20: ......
Page 24: ......
Page 88: ......
Page 158: ......
Page 198: ......
Page 229: ...Using redundant OSPF routing over IPsec VPN 209 THE FORTIGATE COOKBOOK ...
Page 235: ...Using redundant OSPF routing over IPsec VPN 215 THE FORTIGATE COOKBOOK ...
Page 238: ......
Page 239: ...About Fortinet High Performace Network Security Q3 2013 ...
Page 253: ...PRODUCT GUIDE Product Guide ...
Page 265: ......