290
01-28011-0254-20051115
Fortinet Inc.
CLI configuration
VPN
get vpn ipsec vip [<vip_integer>]
show vpn ipsec vip [<vip_integer>]
Example
The following commands add IPSec VIP entries for two remote hosts that can be
accessed by a FortiGate unit through an IPSec VPN tunnel on the
external
interface of the FortiGate unit. Similar commands must be entered on the FortiGate
unit at the other end of the IPSec VPN tunnel.
config vpn ipsec vip
edit 1
set ip 192.168.12.1
set out-interface external
next
edit 2
set ip 192.168.12.2
set out-interface external
end
This example shows how to display the settings for the
vpn ipsec vip
command.
get vpn ipsec vip
This example shows how to display the settings for the VIP entry named
1
.
get vpn ipsec vip 1
This example shows how to display the current configuration of all existing VIP
entries.
show vpn ipsec vip
Configuring IPSec virtual IP addresses
Use the FortiGate unit’s IPSec VIP feature to enable hosts on physically different
networks to communicate with each other as if they were connected to the same
private network. This feature can be configured manually through CLI commands.
When the destination IP address in a local ARP request matches an entry in the
FortiGate unit’s virtual IP (VIP) table, the FortiGate unit responds with its own MAC
address and forwards traffic to the correct destination at the other end of the VPN
tunnel afterward.
ipsec vip command keywords and variables
Keywords and variables
Description
Default
Availability
ip <address_ipv4>
The IP address of the destination
host on the destination network.
0.0.0.0
All models.
out-interface
<interface-name_str>
The name of the FortiGate interface
to the destination network.
null
All models.
Note:
Typing
next
lets you define another VIP address without leaving the vip shell.
Summary of Contents for FortiGate 1000A
Page 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Page 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Page 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Page 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Page 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Page 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Page 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...