IPSec set up
IPSec
Considering the IPSec deployment among more than two FortiWAN devices as the above example.
ISAKMP SA
State
Reason
ISAKMP SA 1
established
For the two FortiWAN devices (FortiWAN1 and FortiWAN 2), the two WAN link IP
addresses, 3.3.3.3 and 5.5.5.5, participate in only ISAKMP SA 1. Although
3.3.3.3 also participates in ISAKMP SA 2, it takes no influence on ISAKMP SA 1
since it is the thing about another device, FortiWAN 3. The deployment limitation
is about any two devices, others can be ignored.
ISAKMP SA 2
established
For the two FortiWAN devices (FortiWAN 2 and FortiWAN 3), the two WAN link
IP addresses, 3.3.3.3 and 8.8.8.8, participate in only ISAKMP SA 2.
ISAKMP SA 3
failed
For the two FortiWAN devices (FortiWAN 1 and FortiWAN 2), the WAN link IP
addresses 6.6.6.6 participates in not only ISAKMP SA 3 but also ISAKMP SA 4.
ISAKMP SA 4
failed
For the two FortiWAN devices (FortiWAN 1 and FortiWAN 2), the WAN link IP
addresses 6.6.6.6 participates in not only ISAKMP SA 3 but also ISAKMP SA 4.
ISAKMP SA 5
established
For the two FortiWAN devices (FortiWAN 2 and FortiWAN 3), thetwo WAN link IP
addresses, 2.2.2.2 and 9.9.9.9, participate in only ISAKMP SA 5. Although
2.2.2.2 also participates in ISAKMP SA 4, it takes no influence on ISAKMP SA 5
since it is the thing about another device, FortiWAN 1. The deployment limitation
is about any two devices, others can be ignored.
FortiWAN Handbook
Fortinet Technologies Inc.
183