286
01-28006-0068-20041105
Fortinet Inc.
Configuring spokes
VPN
Configuring spokes
A remote VPN peer that is functioning as a spoke requires the following configuration:
• A tunnel (AutoIKE phase 1 and phase 2 configuration or manual key configuration)
for the hub.
• The source address of the local VPN spoke.
• The destination address of each remote VPN spoke.
• A separate outbound encrypt policy for each remote VPN spoke. These policies
allow the local VPN spoke to initiate encrypted connections.
• A single inbound encrypt policy. This policy allows the local VPN spoke to accept
encrypted connections.
To create a VPN spoke configuration:
1
Configure a tunnel between the spoke and the hub.
2
Add the source address. One source address is required for the local VPN spoke.
See
“To add an address” on page 200
.
3
Add a destination address for each remote VPN spoke. The destination address is the
address of the spoke (either a client on the Internet or a network located behind a
gateway).
See
“To add an address” on page 200
.
4
Add a separate outbound encrypt policy for each remote VPN spoke. These policies
control the encrypted connections initiated by the local VPN spoke.
The encrypt policy must include the appropriate source and destination addresses
and the tunnel added in step
1
. Use the following configuration:
See
“To add a firewall policy” on page 196
.
5
Add an inbound encrypt policy. This policies controls the encrypted connections
initiated by the remote VPN spokes.
The encrypt policy for the hub must include the appropriate source and destination
addresses and the tunnel added in step
1
. Use the following configuration:
Source
The local VPN spoke address.
Destination
The remote VPN spoke address.
Action
ENCRYPT
VPN Tunnel
The VPN tunnel name added in step
1
. (Use the same tunnel for all encrypt
policies.)
Allow inbound
Do not enable.
Allow outbound
Select allow outbound.
Inbound NAT
Select inbound NAT if required.
Outbound NAT
Select outbound NAT if required.
Содержание FortiGate FortiGate-100A
Страница 24: ...24 01 28006 0068 20041105 Fortinet Inc FortiLog documentation Introduction...
Страница 46: ...46 01 28006 0068 20041105 Fortinet Inc Installing and using a backup firmware image System status...
Страница 72: ...72 01 28006 0068 20041105 Fortinet Inc Transparent mode VLAN settings System network...
Страница 80: ...80 01 28006 0068 20041105 Fortinet Inc DHCP IP MAC binding settings System DHCP...
Страница 114: ...114 01 28006 0068 20041105 Fortinet Inc Access profile options System administration...
Страница 232: ...232 01 28006 0068 20041105 Fortinet Inc CLI configuration Firewall...
Страница 244: ...244 01 28006 0068 20041105 Fortinet Inc peergrp Users and authentication...
Страница 320: ...320 01 28006 0068 20041105 Fortinet Inc service smtp Antivirus...
Страница 366: ...366 01 28006 0068 20041105 Fortinet Inc syslogd setting Log Report...
Страница 380: ...380 01 28006 0068 20041105 Fortinet Inc Glossary...
Страница 388: ...388 01 28006 0068 20041105 Fortinet Inc Index...