![Fortinet FortiWAN Handbook Download Page 203](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088203.webp)
IPSec set up
IPSec
Define Auto Routing and Tunnel Routing policies for an Tunnel Routing over IPSec Transport
mode VPN
As previous descriptions, IPSec Transport mode provides secure data transmission without IP tunneling (IP
encapsulation). However, IPSec Transport mode can give protections to FortiWAN's Tunnel Routing, which brings a
securer (compare to the original TR) and more efficient (compare to the "IPsec Tunnel mode VPN" on load balancing
and fault tolerance) VPN application. Tunnel Routing distributes the encapsulated (GRE) packets over multiple tunnels
(pairs of local WAN port and remote WAN port). With the IPSec SAs established on these TR tunnels, GRE packets
will be protected (encrypted/decrypted) by correspondent SA when they pass through a TR tunnel (the local and
remote WAN ports). Transport-mode IPSec SAs are required for each of Tunnel Routing's GRE tunnels to associate
Tunnel Routing with IPSec.
Example topology for the following policies
IPSec Transport mode protects the communications between private networks behind two FortiWAN units through two
TR tunnels. For this example topology, we need to have configurations of Network Setting, Auto Routing, IPSec and
Tunnel Routing as follows:
Network Setting
Network Setting on the local side:
WAN settings
Go to
System > Network Setting > WAN Setting
FortiWAN Handbook
Fortinet Technologies Inc.
203