FortiGate Lab – BGP over IPSec (VTI) – Web Gui Configuration

This Lab is to summarize the steps how to configure BGP over IPSec on FortiGate firewalls using Custom VPN Creation Wizard.

Custom VPN creatation wizard is the most common used VPN creating wizard if you are create a tunnel between FortiGate and other verndor's device. You can easily convert FortiGate or Cisco VPN template created tunnel to custom tunnel from Web Gui.

 

Diagram

Two Fortigate VMs. 
One is from Azure Test Drive. Another is from my own subscription.

Start Azure Fortigate Test Drive Environment

1 Go to https://azuremarketplace.microsoft.com/en-us/marketplace/apps/fortinet.fortinet-fortigate?ocid=FortiGate_202105_landingpage_en-us  or https://www.fortigate-azure.com/. Choose a Test Drive, sign in and agree to the terms of use.


2 After system complete the provisioning, you will get a page to tell you Your Test Drive is ready. The testdrive lab will last for three hours. 

Once you complete the form, your Test Drive will start deploying. In addition to the webpage information, in a few minutes you will also get an email notification that the environment is ready. Just follow instructions in the webpage or in the email, and you will be able to access a fully provisioned and ready to use environment.


3 After three hours if you have not completed the test drive use case, you still have a chance to repeat test drive to try it again. 

4 When the Test Drive is ready click on the FortiGate link to open the GUI.

Log in to Web GUI Console using following credential:
  • username: ftnt-testdrive 
  • password: Fortinet@123

Create IPSec VPN Using Custom VPN Wizard

1 VPN Creation Wizard - Choose custom

Pre-shared Key & IKE v1 Main Mode & Phase 1 Proposal

Phase 2 Proposal

2 Complete VPN Configuration on both sides. 

3 Create bi-directional Firewall Policy rules

On NetSec site, I have to enable NAT on the rule which allows tunnel traffic to lan as show below

4 Create static route

5 Test from Test site to Netsec site

Testing from Windows machine 10.1.1.5. 
Trying to ping from Test site to NetSec site, I have to enable NAT to make ping works
C:/Users/netsec>tracert 10.254.0.9 Tracing route to 10.254.0.9 over a maximum of 30 hops 1 1 ms <1 ms <1 ms 10.1.1.4 2 * * * Request timed out. 3 8 ms 7 ms 7 ms 10.254.0.9 PS C:/Users/netsec> Test-NetConnection -ComputerName 10.254.0.9 -Port 22 ComputerName : 10.254.0.9 RemoteAddress : 10.254.0.9 RemotePort : 22 InterfaceAlias : Ethernet SourceAddress : 10.1.1.5 TcpTestSucceeded : True Traffic log can be found from page Log & Report - Forward Traffic  

Enable BGP

 

Troubleshooting & Diag

Videos

 

References

版权声明:
作者:Alex
链接:https://www.techfm.club/p/129151.html
来源:TechFM
文章版权归作者所有,未经允许请勿转载。

THE END
分享
二维码
< <上一篇
下一篇>>