![Fortinet FortiWAN Handbook Download Page 187](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088187.webp)
IPSec set up
IPSec
you need to make sure that the IKE Phase 1 proposals on the two FortiWAN units are exactly the same, or Phase 1
negotiation goes to failure.
IKE Phase 1 Web UI fields
Go to Service > IPsec, select the Tunnel Mode or Transport Mode and click the add button to add a new configuration
panel of Phase 1. The Phase 1 configuration defines the endpoints of the IPSec VPN tunnel, and the necessary
parameters used to negotiate with the opposite unit to establish ISAKMP Security Association.
Add / Delete / Move-Up /
Move-Down
The buttons for:
l
Adding a new configuration panel below current Phase 1
configuration
l
Deleting the current Phase 1 configuration (all the Phase 2
configurations belong to the Phase 1 configuration will be deleted as
well)
l
Moving the current Phase 1 configuration up a row
l
Moving the current Phase 1 configuration down a row
Packets that matching a Phase 2's Quick Mode selector or Phase 1's
[Local IP, Remote IP] are allowed to pass through the
correspondent IPSec VPN. However, both the two filters are
required to be incompatible with the others, Phase 1 configurations
moving-up or moving-down is nothing about rule first-match.
Name
A "unique" description name for the Phase 1 definition. The name is
not a parameter exchanged with the opposite unit during Phase 1
negotiations. This name can contain a piece of information used for
simple management, such as it can reflect where the correspondent
remote unit is or what the purpose it is. It is also the index used in
IPSec Statistics (See "
").
Hide Details / Show Details
Click to expand or collapse the configuration details.
Local IP
Type the IP address of local FortiWAN's WAN port used to establish
the IPSec VPN tunnel with remote FortiWAN unit. Packets of IKE
negotiations (Both Phase 1 and Phase 2) and IPSec VPN
communications are transferred through the WAN port on the local
side. Note that only static IP address is supported, please make
sure the WAN link type is
Routing Mode
,
Bridge Mode: One
Static IP
or
Bridge Mode: Multiple Static IP
.
The local IP address must equal to the Remote IP on the opposite
unit that the local unit establish the IPSec VPN with.
FortiWAN Handbook
Fortinet Technologies Inc.
187