最新公告 |
当前位置: 首页 > 新闻与文档 > SonicWall配置 >

fortigate to sonicwall vpn setup

时间:2012-04-27 11:03来源:港湾互联网络 作者:港湾网络编辑 点击:
configure the fortigate unitconfigure the phase1 and phase 2 vpn settingsto configure the phase1 settingsgo to vpn ipsec phase 1. select create new an

configure the unitconfigure the phase1 and phase 2 settings

to configure the phase1 settings

  • go tovpn>ipsec>phase 1.
  • select create new and enter the following:

    gateway name:
    remote gateway:static ip
    ip address:ip address
    mode:main
    authentication method:preshared key
    pre-shared key:preshared key
  • select advanced and enter the following:

    encryption:3des
    authentication:sha1
    dh group:2
    keylife:28800
    leave all other settings as their default.
  • select ok.
  • to configure the phase 2 settings

  • go tovpn>ipsec>phase 2.
  • select create new and enter the following:

    tunnel name:sonicwall
    remote gateway:select sonicwall
  • select advanced and enter the following:

    encryption:3des
    authentication:sha1
    dh group:2
    keylife:28800
    internet browsing:none
    quick mode identities:use selectors from policy
  • select ok.
  • add a firewall policy

    add an the source and destination addresses and add an internal to external policy that includes these source and destination addresses to permit the traffic flow.

    to add the addresses

  • go tofirewall>address.
  • select create new to create the fortigate address.
  • enter a name for the address, for example fortigate_network.
  • enter the fortigate ip address and subnet.
  • select ok.
  • select create new again to create the sonicwall address.
  • enter the name for the address, for example sonicwall_network.
  • enter the sonicwall ip address and subnet.
  • select ok.
  • to create a firewall policy for the vpn traffic going from the fortigate unit to the sonicwall device

  • go tofirewall>policy.
  • select create new and set the following:

    source interface:internal
    source address:fortigate_network
    destination interface:sonicwall_network
    destination address:wan1 (or external)
    schedule:always
    service:any
    action:encrypt
    vpn tunnel:sonicwall
    select allow inbound
    select allow outbound
  • select ok.
  • to create a firewall policy for the vnp traffic going from the sonicwall device to the fortigate unit

  • go tofirewall>policy.
  • select create new and set the following:

    source interface:wan1 (or external)
    source ip address:sonicwall_network
    destination interface:internal
    destination address name:fortigate_network
    schedule:always
    service:any
    action:encrypt
    vpn tunnel:sonicwall
    select allow inbound
    select allow outbound
  • select ok.
  • configure the sonicwall device

    create the address object for the fortigate unit to identify the fortigate unit's ip address for the vpn security association (sa).

    to create an address entry

  • go tonetwork>address objects.
  • select add and enter the following:

    name:fortigate_network
    zone assignment:vpn
    type:network
    network:fortigate ip address
    netmask:fortigate netmask
  • select ok.
  • configure the vpn settings for the vpn tunnel connection.

  • to configure the vpn, go to vpn.
  • ensure enable vpn is selected in the vpn global settings section.
  • select add in the vpn policies area.
  • select the general tab and configure the following:
    ipsec keying mode:ike using preshared secret.
    name:fortigate_network
    ipsec primary gateway name or address:ipsec gateway ip address
    shared secret:preshared
    local ike id:ip address (address left empty)
    peer ike id:ip address (address left empty)

  • select the network tab and configure the following:
  • for the local networks, select choose local network from list and select lan primary subnet.
  • for the destination networks, select choose destination network from list and select fortigate_network.

  • select the proposals tab and configure the following:

    ike (phase1) proposalexchange:main mode
    dh group:group 2
    encryption:3des
    authentication:sha1
    life time:28800
    ike (phase2) proposalprotocol:esp
    encryption:3des
    authentication:sha1
    dh group:group 2
    life time:28800

  • select the advanced tab and select enable keep alive.
  • select ok.

  • [版权声明]bsd爱好者乐园站内文章,如来源不是互联网,则均系原创或翻译之作,可随意转载,或以此为基础进行演译,但务必以链接形式注明原始出处和作者信息,否则属于侵权行为。另对本站转载他处文章,俱有说明,如有侵权请联系本人,本人将会在第一时间删除侵权文章。
    [站长微博]欢迎访问剑心通明的腾讯微博,  bsd爱好者微群,  点击此处开通微博同时与剑心互听


    tag:

    (责任编辑:admin)
    顶一下
    (0)
    0%
    踩一下
    (0)
    0%
    ------分隔线----------------------------
    发表评论
    请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
    评价:
    用户名: 验证码: 点击我更换图片
    栏目列表
    推荐内容
    驱白巴布期片 白癜风的发病原因 复方卡力孜然酊 白癜风早期能治愈吗 北京军颐中医医院 白癜风早期能治愈吗 北京军颐中医医院 北京军颐中医医院 补骨脂注射液 白癜风症状 白癜风治疗医院 北京白癜风医院 治疗白癜风最好的方法 北京军颐中医医院 头部白癜风的症状 白癜风传染吗 白癜风的发病原因 北京白癜风医院哪家好 白癜风的危害 白癜风早期症状 白癜风的治疗 白癜风症状 白癜风治疗 专业治疗白癜风医院哪家好 白癜风早期能治愈吗 白癜风症状 白癜风能治愈吗 白癜风治疗 白癜风治疗方法 白癜风怎么治疗 儿童白癜风发病的原因 白癜风的危害 白癜风治疗要花多少钱 白癜风去哪里治疗最好 白癜风治疗医院 如何治疗白癜风好 白癜风能治愈吗 什么方法治疗白癜风好 廊坊治疗白癜风最好的专科医院 白癜风怎么治疗好 白癜风早期能治愈吗 白癜风哪里治疗好 治疗白癜风的偏方有哪些 怎么治疗白癜风好 石家庄白癜风最好的医院 怎么治疗白癜风好 治疗白癜风哪家医院好 治疗牛皮癣,北京牛皮癣医院 白癜风治疗最好医院 白癜风能治愈吗 白癜风能治愈吗 白癜风早期症状 白癜风专科医院 治疗白癜风医院 白癜风早期症状是怎么样 天津治疗白癜风哪家医院效果最好 北京白癜风军颐中医医院 白癜风治疗医院 白癜风如何治疗 白癜风医院 治疗白癜风最好医院 牛皮癣 牛皮癣治疗 牛皮癣医院 治疗白癜风多少钱 北京治疗白癜风最好医院 白癜风早期症状 治疗白癜风偏方
    How To Get Rid Of Stretch Marks
    How to Get Rid of Acne Scars
    how to get rid of flakes
    how to ask a girl out
    how to get a girl to like you
    How To Talk To Girls
    How To Impress A Girl