type
status
date
summary
tags
category
URL
password
slug
icon
This is a quick reference on how to configure BGP over IPSEC VPN Fortigate CLI.
1. Scenario

2. Configure Firewall “BGP1”
2.1 Configure VPN IPSEC phase1-interface
2.2 Configure VPN IPSEC phase2-interface
2.3 Configure firewall policies
2.4 Edit VPN interface
You will need to configure an IP address on either end of the tunnel including the corresponding remote IP address of the remote device.
2.5 Configure BGP
Configure the IP address of the remote ends IPSEC VPN interface as the neighbour address as per step 2.4.
3. Configure Firewall BGP2
3.1 Configure VPN IPSEC phase1-interface
3.2 Configure VPN IPSEC phase2-interface
3.3 Configure firewall policies
3.4 Edit VPN interface
3.5 Configure BGP
4. Diagnosis
4.1 Check the VPN tunnel is up
If the phase 2 tunnel is down you will see no SA’s (security associations) – for example sa=0
4.2 Check the BGP neighbour is up
4.3 Check the BGP routing table
4.4 Ping test from host to host
Thank you for reading and please feel free to leave any feedback.
- How to configure OSPF over IPSEC VPN Fortigate CLI.
DateJanuary 13, 2021
- How to create a Site to Site IPSec VPN from a pfSense to a Fortigate behind a NAT Router.
DateJuly 3, 2019
- How to debug an IPSEC VPN on a Fortigate CLI
DateJuly 3, 2019
Like this:
上一篇
How attackers evade your EDR/XDR system — and what you can do about it | CSO Online
下一篇
自建企业级邮件服务器、域名邮箱!iRedMail 企业级邮件系统搭建、配置、优化教程! – V2RaySSR综合网
- Author:NetSec
- URL:https://blog.51sec.org/article/afc92a15-5e66-40dc-a167-e13ae6330dc5
- Copyright:All articles in this blog, except for special statements, adopt BY-NC-SA agreement. Please indicate the source!