Adding A Vpn Concentrator - Fortinet FortiGate FortiGate-1000 Administration Manual

Fortinet fortigate fortigate-1000: user guide
Hide thumbs Also See for FortiGate FortiGate-1000:
Table of Contents

Advertisement

VPN
FortiGate-1000 Administration Guide
Source
Internal_All
Destination
The VPN spoke address.
Action
ENCRYPT
VPN Tunnel
The VPN spoke tunnel name.
Allow inbound
Select allow inbound.
Allow outbound Select allow outbound.
Inbound NAT
Select inbound NAT if required.
Outbound NAT Select outbound NAT if required.
See
"To add a firewall policy" on page
5
Arrange the policies in the following order:
encrypt policies
default non-encrypt policy (Internal_All -> External_All).

Adding a VPN concentrator

The VPN concentrator collects the hub-and-spoke tunnels into a group. This allows
VPN traffic to pass from one tunnel to the other through the FortiGate unit. With this
configuration, the FortiGate unit functions as a concentrator, or hub, within a hub-and-
spoke network.
Figure 139:Example VPN concentrator configuration
To add a VPN concentrator configuration
1
Go to VPN > IPSEC > Concentrator.
2
Select New to add a VPN concentrator.
3
Enter the name of the new concentrator in the Concentrator Name field.
4
To add tunnels to the VPN concentrator, select a VPN tunnel from the Available
Tunnels list and select the right arrow.
5
To remove tunnels from the VPN concentrator, select the tunnel in the Members list
and select the left arrow.
6
Select OK to add the VPN concentrator.
198.
01-28006-0009-20041105
Hub and spoke VPNs
287

Advertisement

Table of Contents
loading

Table of Contents