Тёмный

FortiGate to FortiGate IPSEC Configuration (FortiOS 6.4.0) 

Fortinet Guru
Подписаться 30 тыс.
Просмотров 53 тыс.
50% 1

This video goes into how to configure an Interface based IPSEC tunnel between two FortiGates that are running FortiOS 6.4.0.
An IPSEC tunnel allows two private networks to communicate with one another over the internet by taking advantage of encryption.
Watch the video and let me know if you have deeper questions.
A troubleshooting video for FortiGate IPSEC tunnels will be coming up soon!
Buy Hardware: bit.ly/2QZVeqh
Get Consulting: bit.ly/36FinSU
My Other Projects:
Office Of The CISO: bit.ly/3HGMH1o
Packet Llama: bit.ly/3SEX3H4
###### SOCIAL LINKS ######
Twitter: bit.ly/2WXiRAv
Facebook: bit.ly/3eigz4D
Instagram: bit.ly/3cZneAz
######################

Опубликовано:

 

9 май 2020

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 82   
@mishmosh1970
@mishmosh1970 2 года назад
This was a great tutorial, very informative, with step-by-step instructions and explanations for a newbie like me, easy to understand.
@daniloalves9928
@daniloalves9928 Год назад
This a great material with a lot of information and explanation and besides step-by-step that can help a newbie to understand.
@jw-5654
@jw-5654 2 года назад
Cheers Mike, I have looked at a lot of other tech videos and you are able to deliver the content at slow pace, not bamboozelling us noobs with a tonne of chaff over complicating things but still giving the right amount of explanation to clearly let us know whats going on and why. Its also very useful that to explain why YOU do things the way YOU do it. I know it takes quite a lot of work to put together these videos but please know that its greatly appreciated. One thing I'd really like to see is a deep dive on debug flow procedures to ascertain traffic flow etc
@glenntembo2693
@glenntembo2693 Год назад
There are many trainers but not all have the gift to deliver, Mike is one of them- he delivers with zeal
@kuteoclinton1033
@kuteoclinton1033 2 года назад
This was simple and easy to undesrtand....i got all the point and possible errors that can be result during the setup
@FortinetGuru
@FortinetGuru 2 года назад
Glad to hear!
@DJDAntoine
@DJDAntoine 2 года назад
Amazing session, reviewing this and my NSE4 studies before jumping into NSE5. Great job and thank you!
@FortinetGuru
@FortinetGuru 2 года назад
Glad I could help!
@rogerrustad
@rogerrustad 4 года назад
Keep up the good work on these videos, Michael.
@FortinetGuru
@FortinetGuru 4 года назад
Thanks, will do!
@aba-nascu
@aba-nascu 4 года назад
Thanks, that's the best explanation so far! Love you content.
@amrbarakat5112
@amrbarakat5112 4 года назад
Thanks, that's the best explanation so far
@JasonLeaman
@JasonLeaman 2 года назад
Thank you for this video, watching this video a few times, i learned alot & also was successfully able to create a Ipsec tunnel from a 61e to an Untangle Firewall. *thumbs Up *
@sergiovenzor6439
@sergiovenzor6439 3 года назад
great video man, i used and it works 100% thanks a lot!!!
@kooolabo
@kooolabo 3 года назад
Thanks! explained very well!
@hifiandrew
@hifiandrew 2 года назад
Good troubleshooting advice. One of the hardest things for me to wrap my brain around when learning routing is that you have to make sure routes work in both directions. I was great at making sure my packet got from router A to router B.. but why doesn't it ping back? Oh router B doesn't know how to reply back to router A.
@RaviChinasamy
@RaviChinasamy 4 года назад
I personally tend to use wizard to create my ipsec tunnel then convert to custom to rework the settings. But definitely going full custom might be better. Cant wait for the SDWAN video 😅!!
@ivanplevneliev4612
@ivanplevneliev4612 2 года назад
Great video rock on! I subscribed!
@rockinron5113
@rockinron5113 Год назад
Great tutorial. Thanks.
@ThisIsTheWay727
@ThisIsTheWay727 Год назад
Short, Simple, and Sweet! S++++++++
@zachthatguy7391
@zachthatguy7391 2 года назад
Love it. Thank you.
@lakshayshow
@lakshayshow 3 года назад
Brilliant sir... thank you very much.
@AlainSylvestre
@AlainSylvestre 4 года назад
Great video. You could draw sometime the layout of your network on your white board.
@DM-rc4yu
@DM-rc4yu 3 года назад
Very useful, thanks.
@ifoam
@ifoam 4 года назад
I know you addressed Blackhole routes in a previous comment but when I learned to create these tunnels, Fortinet recommended those Blackholes. I haven't tested it but they said if the tunnel goes down, traffic for the VPN session will match the default route. If you create a black hole with a higher administrative distance, if the VPN goes down traffic will match the blackhole and go back to the VPN when it comes back up. Without the Blackhole, traffic matches the default route and won't go back to the VPN tunnel when it comes back up. Again, I haven't tested it but that's what they told me when I asked why the wizard was creating those Blackholes. Typing this out, this will probably only affect existing sessions but I think the Blackhole might add a more seamless failure and recreation of a tunnel. Thanks for the video.
@FortinetGuru
@FortinetGuru 4 года назад
I’ve never had a more specific route not get used once a tunnel came back up. Me not experiencing it doesn’t mean it wouldn’t happen though. Best practice is to blackhole routes. I only deal with it on dynamic route tunnels etc for my deployments. I may be setting bad habits by doing that though 😂
@ifoam
@ifoam 4 года назад
@@FortinetGuru Good video none the less! I wish there was better use of named objects with VPNs. It's a huge hassle creating a tunnel with multiple subnets to multiple subnets. Luckily it only has to be done once.
@brahimmellal3227
@brahimmellal3227 3 года назад
thanks i found this really helpfull
@yenisulastri4709
@yenisulastri4709 3 года назад
thanks so much, very useful
@sureshkumar-hc3un
@sureshkumar-hc3un 3 года назад
Thank u bro...for understanding the ipsec concept... could you please post video for ipsec troubleshooting
@DeesoSaeed
@DeesoSaeed 4 года назад
I always try to use named adresses. I use them in statics routing and phase 2 and saves me a lot of typo erros when entering adresses. That's even better when setting up multiple VPN tunnels for redundancy. Another thing I do when using redundancy is grouping vpn interfaces in a zone; then with a just a couple policies and I'm done :D
@WILL_Labscom
@WILL_Labscom 3 года назад
Good job.
@aquariuskamus100
@aquariuskamus100 4 года назад
awesome mate, thank you for sharing It
@FortinetGuru
@FortinetGuru 4 года назад
No problem. If you have any questions or requests just ask!
@alyssabeatrizortinero8735
@alyssabeatrizortinero8735 2 года назад
Thank you
@glenntembo2693
@glenntembo2693 Год назад
Thank you very much Mike wow dude you just untied a knot, count me in- subscribing to join the Guru
@FortinetGuru
@FortinetGuru Год назад
Welcome aboard!
@xloveusa
@xloveusa 2 года назад
thank you
@cetindem74
@cetindem74 3 года назад
Thanks
@mrbptvmovies5470
@mrbptvmovies5470 Год назад
Nice
@arthursena85
@arthursena85 2 года назад
Unusual tranquility
@patrickdenis8567
@patrickdenis8567 2 года назад
quick question related to the reverse policy added after your pings were failing ? why did the IPSEC tunnel was up before if the traffic wasn't allowed ? and thank you for the video !
@tomislavfedek6678
@tomislavfedek6678 3 года назад
Can you make some GNS3 adding virtual fortigate appliance or on another software, it would be very useful
@prashanthnayak6904
@prashanthnayak6904 3 года назад
hello.. i might be wrong but please explain connecting branch fortinet 40F running on 6.4.4 to head office 6.0.11 200D ip sec connections
@justoliz7381
@justoliz7381 4 года назад
Excellent video, I have a question, what would be the steps to be able to access multiple subnet
@FortinetGuru
@FortinetGuru 4 года назад
Add phase 2s for the other subnets and then make sure you have routes and policy to support the traffic.
@tomofedek7613
@tomofedek7613 3 года назад
can you make video about ipsec tunnel with sd wan member
@younmham
@younmham 3 года назад
Can you make a video to explain how to configure a site2site VPN between FortiGate and public VPN provider like NordVPN... ?
@prashanthnayak6904
@prashanthnayak6904 3 года назад
sorry add to below we need redundant as we are using usb dongle and wan in remote site to connect as SDWAN bundle interface to have one interface which will talk to HO (200d 6.0.11) over ipsec.. means if one either wan or usb goes down automatically other link to be as active and take over the connection with in 5 seconds...having one ipsec vpn connections at HO
@prashanthnayak6904
@prashanthnayak6904 3 года назад
since im new to this even vendor is not able to do kindly explain the trouble shooting and connecting ipsec please.. we are able to ipsec om 30E to 200D till 6.2.X but not on 30F 6.4.4
@buttsaabgreat
@buttsaabgreat 2 года назад
what ping-options will be in case of more than one ipsec vpn and also if we have sd-wan configured
@michaelrunyon383
@michaelrunyon383 4 года назад
Do recommend creating Blackhole routes for IPSec destinations, as Fortigate does automatically with the wizard? The claim is a reduction in overhead in the event a remote destination becomes unreachable. Curious what your thoughts are on this are.
@FortinetGuru
@FortinetGuru 4 года назад
I blackhole routes when dynamic routing is in use in full scale enterprise environments. On simpler deployments I usually don’t bother. Worst case, if it isn’t a redundant tunnel the result is the same, no traffic flow.
@michaelrunyon383
@michaelrunyon383 4 года назад
Fortinet Guru thanks for input. Loving the new videos. Keep them coming! I’m excited see some troubleshooting deep dives. Might as well put this pandemic driven downtime to good use! Stay safe and healthy.
@FortinetGuru
@FortinetGuru 4 года назад
You as well!
@Gauravkumar-mb2kv
@Gauravkumar-mb2kv 3 года назад
please make video of ipv6 ipsec in fortinet
@Lukas-zk2zp
@Lukas-zk2zp 3 года назад
Do we need to manually bring up the tunnel from one of the fortigate to trigger the tunnel up?
@FortinetGuru
@FortinetGuru 3 года назад
Auto negotiate and keep alive will auto build. Otherwise interesting traffic will trigger it.
@Spegarinos
@Spegarinos 3 года назад
If we have a profile based firewall, what is the diferrence i the configuration ? Still we must have the static routes ?
@FortinetGuru
@FortinetGuru 3 года назад
Yeah
@nawafXjohn
@nawafXjohn 5 месяцев назад
is creating a Normalized Interface and mapping it to the device only necessary when you're working with fortimanager?
@FortinetGuru
@FortinetGuru 4 месяца назад
It's object oriented coding / association basically. Enables you to normalize what the INSIDE or OUTSIDE (or whatever interface) in your policy is on the actual device itself.
@mazharahmedshaikh7871
@mazharahmedshaikh7871 3 года назад
I need to connect multiple supermarket sites to hq over dydns ipsec vpn. Which is the best fortinet model to use in the hq and supermarket sites
@FortinetGuru
@FortinetGuru 3 года назад
Depends on the bandwidth requirements (total And UTM ) as well as port density and such
@adnananwar4193
@adnananwar4193 4 года назад
what if you have multiple local subnets instead of just one? we want to pass traffic from multiple subnets instead of just one.
@FortinetGuru
@FortinetGuru 4 года назад
Create a phase 2 for each
@osanderr
@osanderr 3 года назад
anyone of you, have configured ipsec using ipv6.. i am try to set up it but, dont come up phase 1
@prashanthnayak6904
@prashanthnayak6904 3 года назад
which we are not able to connect
@aba-nascu
@aba-nascu 4 года назад
Maybe you can show something about FortiManager and explain the best practices regarding implementation with new Fortigates and Fortigates that are already in production ( with rules, vpn an so on). I'm in that position at the moment....new Fortigates (without config) are not a problem but Fortigates that are already in production are not that easy and already existing vpns can not be imported easy......VPN Manager is not a option because you have to create everything new. Maybe you can talk about how other companies are dealing with all those little "obstacles". I hope it makes sense...... :-)
@FortinetGuru
@FortinetGuru 4 года назад
Very good idea
@tonypetreski1243
@tonypetreski1243 3 года назад
So why you don't want to use the Wizard?
@FortinetGuru
@FortinetGuru 3 года назад
I like custom. Having subnets and not automated address objects etc.
@aba-nascu
@aba-nascu 4 года назад
Any idea when 6.2.4 will be released?
@FortinetGuru
@FortinetGuru 4 года назад
Mid May is word on the street
@lastofdev777
@lastofdev777 3 года назад
It'll better if you showed us your topology.
@maxu6830
@maxu6830 4 года назад
FGT to FGT is easier than between 2 différents products (FGT to StrongSwan for exemple).. if someone have a config guide, i'm interested 😁 ! Wait debug video 🤞
@tovarasultau
@tovarasultau 4 года назад
I woul like to see a double nat ipsec vpn.
@ssse3123
@ssse3123 2 года назад
Fortinet tutorials with a Cisco DNA shirt. This guy just doesn't care. 😅
@sebschrader
@sebschrader 3 года назад
A 10.x.y.0/24 subnet is NOT class C! Classes are defined by the first bits of an address. Classful addressing is obsolete since 1993. Please don't use class nomenclature anymore.
@hifiandrew
@hifiandrew 2 года назад
and the fact one is using CIDR notation means it is class-less lol
Далее
FortiGate SSL VPN Configuration (FortiOS 6.4.0 Basic)
26:27
Ummmm We "HAIR" You!
00:59
Просмотров 2,4 млн
Site to Site Vpn Fortigate with Fortigate
22:59
Просмотров 1,8 тыс.
FortiGate: Application Control (FortiOS 6.4.0)
18:15
Просмотров 53 тыс.
IPSEC: What is it and how does it work
15:07
Просмотров 12 тыс.
My FortiGate SDWAN Configuration and Some Use Cases
16:25
FortiGate FortiOS 7.2.4 Walk Through
34:10
Просмотров 18 тыс.
Configure IPSec VPN between FortiGate in Hindi
35:54