![Fortinet FortiWAN Скачать руководство пользователя страница 180](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088180.webp)
IPSec
IPSec set up
FortiWAN unit to recover the original GRE packets, and the subsequence is the normal Tunnel Routing processes,
packet decapsulation, reassembly and forwarding (to the hosts behind the FortiWAN). The way for IPSec Transport
mode to protect Tunnel Routing transmission is very flexible. For every TR tunnel of a tunnel group, it is your options
to establish a IPSec SA protecting the TR tunnel or not. Tunnel Routing works normally under full and partial IPSec
protection (full protection: each TR tunnel of a tunnel group is protected by a IPSec SA; partial protection: parts of the
TR tunnels of a tunnel group are protected by IPSec SAs).
In conclusion, FortiWAN provides three methods to build a VPN network, which are
Tunnel Routing
,
IPSec Tunnel
mode
and
Tunnel Routing over IPSec Transport mode
. Note that Tunnel Routing can not support dynamic IP
and NAT pass-through (one of the features of Tunnel Routing, see "Dynamic IP addresses and NAT pass through" in
"Tunnel Routing > How the Tunnel Routing Works"), if it is protected by IPSec.
Type
IPSec protection Tunneling
Bandwidth
Aggregation &
Fault Tolerance
Peer device
IPSec Tunnel
mode
Yes
Yes
No
Peer can be a
FortiWAN or a
FortiGate
Tunnel Routing
No
Yes
Yes
Peer must be a
FortiWAN
Tunnel Routing
over IPSec Trans-
port mode
Yes
Yes
Yes
Peer must be a
FortiWAN
Limitation in the IPSec deployment
FortiWAN IPsec has an intrinsic limitation in establishing ISAKMP Security Associations. For the establishment of
ISAKMP SA between
any two devices
,
one IP address of a WAN link of a FortiWAN device is restricted to
participate in only one ISAKMP SA
. The mapping of WAN link IP addresses for establishing ISAKMP SAs
between any two devices must be
one-to-one
. The negotiations of ISAKMP SAs go to failure (the subsequent
negotiations of IPSec SAs abort so that) if those Phase 1 configurations on any two FortiWAN devices contain a
common WAN link IP address, no matter on the local side or remote side. The following diagrams give the clear
explanation of this in details.
180
FortiWAN Handbook
Fortinet Technologies Inc.
Содержание FortiWAN
Страница 1: ...FortiWAN Handbook VERSION 4 2 1...