Page 1
Description: This technical note demonstrates how to set up an IPSec VPN tunnel between a FortiGate-800 Antivirus Firewall and a Cisco Systems VPN 3000 Concentrator. In the configuration example, the two VPN peers use preshared keys to authenticate each other.
Page 2
No part of this publication including text, examples, diagrams or illustrations may be reproduced, transmitted, or translated in any form or by any means, electronic, mechanical, manual, optical or otherwise, for any purpose, without prior written permission of Fortinet Inc. FortiGate to Cisco VPN 3000 Concentrator Interoperability Technical Note FortiGate v2.80 MR7...
Computers on private Network_2 behind the VPN 3000 Concentrator can access private Network_1 through the FortiGate-800 unit. All traffic generated by computers on Network_2 is subject to a FortiGate firewall encryption policy. Figure 1: FortiGate-800 to VPN 3000 Concentrator IPSec VPN example...
VPN 3000 Concentrator and establish a secure connection. For the purposes of this example, a preshared key will be used to authenticate the VPN 3000 Concentrator. The same preshared key must be specified at the FortiGate-800 and the VPN 3000 Concentrator.
FortiGate to Cisco VPN 3000 Concentrator Interoperability The key must contain at least 6 printable characters and should only be known by network administrators. For optimum protection against currently known attacks, the key should consist of a minimum of 16 randomly chosen alphanumeric characters. To define the phase 1 parameters Go to VPN >...
Select Create New, enter the following information, and select OK: Address Name Enter an address name (for example, Network_2). IP Range/Subnet Enter the IP address of the private network behind the VPN 3000 Concentrator (for example, 10.180.2.0/24). 01-28007-0180-20050328 Fortinet Inc.
FortiGate to Cisco VPN 3000 Concentrator Interoperability To define the firewall encryption policy Go to Firewall > Policy. Select Create New, enter the following information, and select OK: Interface/Zone Source Select the interface to the internal (private) network. For example, port1. Destination Select the interface to the external (public) network.
Page 10
FortiGate to Cisco VPN 3000 Concentrator Interoperability Enter the following information, and select Apply: Enable Select the option. Name Type a name for the LAN-to-LAN connection (for example, FortiGate-800). Interface Ethernet 2 (Public) (192.168.4.2) Connection Type Bi-directional Peers Type the IP address of the FortiGate interface to the external (public) network (for example, 192.168.100.99).
FortiGate to Cisco VPN 3000 Concentrator Interoperability Monitoring and testing the VPN tunnel The FortiGate unit provides a number of tools for viewing and testing IPSec VPN tunnels: • You can display the IPSec VPN tunnel list to view the status of all IPSec VPN tunnels.
Page 12
FortiGate to Cisco VPN 3000 Concentrator Interoperability 01-28007-0180-20050328 Fortinet Inc.
Need help?
Do you have a question about the FortiGate-800 and is the answer not in the manual?
Questions and answers