Solved

Site-to site VPN fortigate and cisco router

Posted on 2015-02-06
3
1,953 Views
Last Modified: 2015-02-07
Hello;
How can i configure site-to site IPSEC VPN between fortigate (dynamic IP) and Cisco router(static IP)?
0
Comment
Question by:PMCCCC
3 Comments
 
LVL 62

Accepted Solution

by:
btan earned 500 total points
ID: 40595553
key is to ensure the IPSec phase 1 and 2 setting are same in Fortigate and Cisco, you can check out the Dynamic IP (you need an account from the dynamic dns service subscribed) in guide and note this
IPsec VPN expects an IP address for each end of the VPN tunnel. All configuration and communication with that tunnel depends on the IP addresses as reference points. However, when the interface the tunnel is on has DDNS enabled there is no set IP address. The remote end of the VPN tunnel now needs another way to reference your end of the VPN tunnel. This is accomplished using Local ID.
(See Dynamic DNS over VPN section and the later section on an example for Branch 1 using static and Branch 2 for Dynamic) http://docs.fortinet.com/uploaded/files/1881/fortigate-ipsec-52.pdf

However, the above example is Fortigate at both each end, hence you can catch how to configure Cisco router (see R1) to pt to a Dynamic VPN device (example stated R2 and R3) in this. The key pt to note is use of "crypto isakmp key <Secret> address 0.0.0.0 0.0.0.0"  to define the remote as Dynamic
http://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/936-cisco-router-vpn-dynamic-endpoint.html

For interest, the below example is doing static part of Cisco and Fortigate. The GUI flow is useful
http://blog.webernetz.net/2015/02/02/ipsec-site-to-site-vpn-fortigate-cisco-router/
0
 

Author Comment

by:PMCCCC
ID: 40595598
Thanks btan that was very helpful.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Radius setup on a Cisco Switch with Server 2012 23 51
SBS 2008 cannot logon remotely 7 47
Firmware for ISR4321 Router 6 33
RDP ISR4321 Cisco Router 7 23
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now