VPN
Hub and spoke VPNs
FortiGate-500A Administration Guide
01-28006-0100-20041105
289
See
“To add a firewall policy” on page 200
.
5
Arrange the policies in the following order:
• encrypt policies
• default non-encrypt policy (Internal_All -> External_All).
Adding a VPN concentrator
The VPN concentrator collects the hub-and-spoke tunnels into a group. This allows
VPN traffic to pass from one tunnel to the other through the FortiGate unit. With this
configuration, the FortiGate unit functions as a concentrator, or hub, within a hub-and-
spoke network.
Figure 139:Example VPN concentrator configuration
To add a VPN concentrator configuration
1
Go to
VPN > IPSEC > Concentrator
.
2
Select New to add a VPN concentrator.
3
Enter the name of the new concentrator in the Concentrator Name field.
4
To add tunnels to the VPN concentrator, select a VPN tunnel from the Available
Tunnels list and select the right arrow.
5
To remove tunnels from the VPN concentrator, select the tunnel in the Members list
and select the left arrow.
6
Select OK to add the VPN concentrator.
Source
Internal_All
Destination
The VPN spoke address.
Action
ENCRYPT
VPN Tunnel
The VPN spoke tunnel name.
Allow inbound
Select allow inbound.
Allow outbound
Select allow outbound.
Inbound NAT
Select inbound NAT if required.
Outbound NAT
Select outbound NAT if required.
Summary of Contents for FortiGate FortiGate-500A
Page 24: ...24 01 28006 0100 20041105 Fortinet Inc Customer service and technical support Introduction...
Page 46: ...46 01 28006 0100 20041105 Fortinet Inc Changing the FortiGate firmware System status...
Page 72: ...72 01 28006 0100 20041105 Fortinet Inc FortiGate IPv6 support System network...
Page 80: ...80 01 28006 0100 20041105 Fortinet Inc Dynamic IP System DHCP...
Page 110: ...110 01 28006 0100 20041105 Fortinet Inc FortiManager System config...
Page 116: ...116 01 28006 0100 20041105 Fortinet Inc Access profiles System administration...
Page 134: ...134 01 28006 0100 20041105 Fortinet Inc Shutdown System maintenance...
Page 248: ...248 01 28006 0100 20041105 Fortinet Inc CLI configuration Users and authentication...
Page 324: ...324 01 28006 0100 20041105 Fortinet Inc CLI configuration Antivirus...
Page 386: ...386 01 28006 0100 20041105 Fortinet Inc Glossary...
Page 394: ...394 01 28006 0100 20041105 Fortinet Inc Index...