{"id":4110,"date":"2019-05-10T04:34:51","date_gmt":"2019-05-10T04:34:51","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=4110"},"modified":"2024-02-01T05:56:05","modified_gmt":"2024-02-01T05:56:05","slug":"ipsec-fortigate-fortinet-vpn","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/ipsec-fortigate-fortinet-vpn","title":{"rendered":"IPSEC Fortigate\/Fortinet VPN Config"},"content":{"rendered":"\n<ol class=\"wp-block-list\">\n<li>Add VPN profile to both sides with same PreShared Key<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"646\" height=\"529\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/05\/img_5cd4fff2cf7ed.png\" alt=\"\" class=\"wp-image-4114 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/05\/img_5cd4fff2cf7ed.png 646w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/05\/img_5cd4fff2cf7ed-300x246.png 300w\" sizes=\"auto, (max-width: 646px) 100vw, 646px\" \/><\/figure>\n\n\n\n<p id=\"DZbeMMN\">&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"931\" height=\"560\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2020\/08\/img_5f36149ee0a5e-e1652398602723.png\" alt=\"\" class=\"wp-image-4755 img-responsive\" style=\"width:840px;height:auto\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2020\/08\/img_5f36149ee0a5e-e1652398602723.png 931w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2020\/08\/img_5f36149ee0a5e-e1652398602723-300x180.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2020\/08\/img_5f36149ee0a5e-e1652398602723-768x462.png 768w\" sizes=\"auto, (max-width: 931px) 100vw, 931px\" \/><\/figure>\n\n\n\n<p><strong>USE PFS for Phase 2 Auto Neg<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"663\" height=\"343\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/05\/img_627d99d53f6f5.png\" alt=\"\" class=\"wp-image-5774 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/05\/img_627d99d53f6f5.png 663w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/05\/img_627d99d53f6f5-300x155.png 300w\" sizes=\"auto, (max-width: 663px) 100vw, 663px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"595\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2020\/08\/img_5f36148632bb1.png\" alt=\"\" class=\"wp-image-4754 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2020\/08\/img_5f36148632bb1.png 1024w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2020\/08\/img_5f36148632bb1-300x174.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2020\/08\/img_5f36148632bb1-768x446.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>2) Add Static Routes on both sides to each other&#8217;s Subnets via the VPN Connection Interface created in Step 1<\/p>\n\n\n\n<p>3) Add Policies<\/p>\n\n\n\n<p>WAN-&gt;VPN Connection Interface created in Step 1 ( without NAT )&nbsp;<\/p>\n\n\n\n<p>VPN Connection Interface created in Step 1 -&gt; All&nbsp; ( without NAT )&nbsp;<\/p>\n\n\n\n<p>***********<\/p>\n\n\n\n<p>DES and 3DES does not need as strong a DH group, however DES and 3DES should never be used unless you are under some encryption restriction based on country restriction. &nbsp;AES should use a stronger DH Group. &nbsp;If you are using encryption or authentication algorithms with a 128-bit key, use Diffie-Hellman groups 19, 20. If you are using encryption or authentication algorithms with a 256-bit key or higher, use Diffie-Hellman group 21.&nbsp;<a href=\"https:\/\/tools.ietf.org\/html\/rfc5114\" target=\"_blank\" rel=\"noreferrer noopener\">RFC 5114<\/a>&nbsp;Sec 4 states DH Group 24 strength is about equal to a modular key that is 2048-bits long, that is not strong enough to protect 128 or 256-bit AES, you should stay away<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; USE PFS for Phase 2 Auto Neg 2) Add Static Routes on both sides to each other&#8217;s Subnets via the VPN Connection Interface created in Step [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1251,1250,1530,1351],"class_list":["post-4110","post","type-post","status-publish","format-standard","hentry","category-research","tag-fortigate","tag-fortinet","tag-ipsec","tag-vpn"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/4110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=4110"}],"version-history":[{"count":6,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/4110\/revisions"}],"predecessor-version":[{"id":7639,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/4110\/revisions\/7639"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=4110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=4110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=4110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}