This post is to record all steps to configure a ipsec site to site IPSec VPN tunnel between Palo Alto Firewall and Fortigate Firewall,
Diagram
 Online Updated Diagram:Configure Basic settings of Palo Alto FirewallÂ
More details can be found from following posts:Â1Â Download Palo Alto Image
2Â Import Image and Configure VM
3Â Connect to Mgmt Interface
4Â Configure Internal/Internet interfaces.
5Â Configure Security Zone and Virtual Router
6Â Configure Security policy and NAT
7Â Test
Configure Basic settings of Fortigate FirewallÂ
More details can be found from this post:Â https://blog.51sec.org/2022/01/download-and-launch-fortigate-virtual.html1Â Download VM image
2Â Import into VMWare Workstation lab environment
3Â Configure static ip and http access for mgmt interface and using HTTP to connect to mgmt interface
4Â Config LAN/WAN/DMZ interfaces
5Â Config basic security policy and nat
6Â TestConfigure VPN tunnel in Palo Alto FirewallÂ
Â1Â Create IKE Crypto Profile
2Â Create IPSec Crypto Profile
3Â Create IKE Gateway
4Â Create tunnel interface
You do not have to assign an ip address for your tunnel interface. But if assigned, it can be used to monitor tunnel.Â
5Â Create IPSec Tunnel
6Â Virtual Router Static Route configuration
Depends on how you routing your traffic, after you add your tunnel interface into your virtual router, you might need to create a couple static routes.
7Â Create security policy rule to allow VPN networks to access each other.
Configure VPN tunnel in Fortigate FirewallÂ
Â1Â Go to VPN section, choose IPsec Tunnels and click Create New IPsec Tunnel
2Â Start VPN setup. Put name, choose template type, if need NAT, and select remote device type
3Â Configure Authentication method and remote gateway information
4Â Choose local ip segment and configure remote ip segment. This traffic will be your interest traffic which will be sent to VPN tunnel.
5Â Review and create tunnel configuration
6Â Fortigate VPN Wizard will auto-generate tunnel interface, static route to tunnel, and policy rule to allow traffic between vpn networks.
Test
Â
On Fortigate,Â
On Palo Alto:
Videos
ÂIPSec VPN Tunnel Setup:
No comments:
Post a Comment