Jump to content

Recommended Posts

Posted

Ok so we have fortigate firewall appliance in one school and a GfL firewall appliance in another. I need to set up a VPN between the 2 LANs. The ISP providing the fortigate have set up their side and have passed me details for GfL to put into their firewall. The GfL are saying no we don't do that. You need to set the IPsec connection from a client within your LAN. So I have a server which could be used but I have no idea how to set it up for an IPsec VPN. The Fortigate ISP have given me settings for Phase 1, Phase 2 and a pre-shared key but I have no idea where I put those into the server to get a connection up and running.

 

Any helpers out there?

Posted

Hi Fiza,

 

if the ISP in questions is us then you can do a client IPSEC VPN using Forticlient or SSL (recommended). You can assign different users in AD as VPN users or create your own user group on the Fortigate. The downside of doing this is you'll need to click connect on the Forticlient VPN software each time you turn your PC on or want to dial-in to the remote network. Also by default it'll be a "one way tunnel" meaning you can only instigate connections from the clients, not the other way around.

 

If you were to do a proper site to site IPSEC VPN then you can allow any IP from one site to access any IP from another site or create access list rules and UTM profiles to protect both sites.

 

Not sure why the GFL won't support this. Pretty standard stuff we already work with other GFL's and LA's.

 

Let me know if I can help any more.

 

Thanks

 

Dave

  • Thanks 1
Posted
We basically want to be able connect to the SB school to backup some of their data to our network and some of ours to theirs. We could also use the connection to do remote support
Posted

I'd recommend a site to site VPN then, client won't really do it because of NAT which will occur via the IPSEC or SSL interface on the client so traffic can only be initiated 1 way.

 

IPSEC tunnels have been about for nearly as long as I've been in the industry so I can't understand why the GFL couldn't support this.

 

Dave

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...