{"id":9196,"date":"2025-08-30T04:50:46","date_gmt":"2025-08-30T04:50:46","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=9196"},"modified":"2025-08-30T05:11:35","modified_gmt":"2025-08-30T05:11:35","slug":"fortigate-device-to-opnsense-site-to-site-vpn","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/fortigate-device-to-opnsense-site-to-site-vpn","title":{"rendered":"Fortigate Device to Opnsense Site to Site VPN"},"content":{"rendered":"\n<p>Example IP of OpnSense : 1.1.1.1<\/p>\n\n\n\n<p>Local IP of OpenSense : 172.40.1.0\/24<\/p>\n\n\n\n<p>Example IP of Forti : 2.2.2.2<\/p>\n\n\n\n<p>Local IP of Forti : 192.168.13.0\/24<\/p>\n\n\n\n<p><strong>Forti Config<\/strong><\/p>\n\n\n\n<p>( Remember to add Static Routes and Policies with NAT ) <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">config vpn ipsec phase1-interface\n    edit \"Forti-Opn\"\n        set interface \"port1\"\n        set ike-version 2\n        set keylife 28800\n        set peertype any\n        set net-device disable\n        set proposal aes256-sha256\n        set dhgrp 14\n        set nattraversal enable\n        set transport auto\n        set remote-gw 1.1.1.1\n        set psksecret \"[REDACTED]\"\n    next\nend\nconfig vpn ipsec phase2-interface\n    edit \"Phase2\"\n        set phase1name \"Forti-Opn\"\n        set proposal aes256-sha256\n        set dhgrp 14\n    next\nend<\/code><\/pre>\n\n\n\n<p><strong>OpnSense<\/strong> <strong>Config<\/strong><\/p>\n\n\n\n<p>You will need to whitelist VPN Ports on WAN<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2025\/08\/image-34.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"272\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2025\/08\/image-34.png\" alt=\"\" class=\"wp-image-9202 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2025\/08\/image-34.png 1024w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2025\/08\/image-34-300x80.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2025\/08\/image-34-768x204.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">&lt;preSharedKey uuid=\"7c6e2937-4669-40c8-8d40-bfb61f263fa2\">\n  &lt;ident>1.1.1.1&lt;\/ident>\n  &lt;remote_ident>2.2.2.2&lt;\/remote_ident>\n  &lt;keyType>PSK&lt;\/keyType>\n  &lt;Key>[REDACTED]&lt;\/Key>\n  &lt;description>FG-PSK&lt;\/description>\n&lt;\/preSharedKey><\/code><\/pre>\n\n\n\n<p>IPSECConfig<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code class=\"\">&lt;Connection uuid=\"42820841-7655-4c82-ba28-69819916dcdb\">\n  &lt;enabled>0&lt;\/enabled>\n  &lt;proposals>aes256-sha256-modp2048&lt;\/proposals>\n  &lt;unique>no&lt;\/unique>\n  &lt;aggressive>0&lt;\/aggressive>\n  &lt;version>2&lt;\/version>\n  &lt;mobike>1&lt;\/mobike>\n  &lt;local_addrs>1.1.1.1&lt;\/local_addrs>\n  &lt;local_port\/>\n  &lt;remote_addrs>2.2.2.2&lt;\/remote_addrs>\n  &lt;remote_port\/>\n  &lt;encap>0&lt;\/encap>\n  &lt;reauth_time\/>\n  &lt;rekey_time\/>\n  &lt;over_time\/>\n  &lt;dpd_delay>10&lt;\/dpd_delay>\n  &lt;dpd_timeout\/>\n  &lt;pools\/>\n  &lt;send_certreq>1&lt;\/send_certreq>\n  &lt;send_cert\/>\n  &lt;keyingtries\/>\n  &lt;description>RLBV -FG-S2S&lt;\/description>\n&lt;\/Connection>\n&lt;local uuid=\"9edd4249-c87d-44ef-8cd7-9db703031d2a\">\n  &lt;enabled>1&lt;\/enabled>\n  &lt;connection>42820841-7655-4c82-ba28-69819916dcdb&lt;\/connection>\n  &lt;round>0&lt;\/round>\n  &lt;auth>psk&lt;\/auth>\n  &lt;id>1.1.1.1&lt;\/id>\n  &lt;eap_id\/>\n  &lt;certs\/>\n  &lt;pubkeys\/>\n  &lt;description>LocalID&lt;\/description>\n&lt;\/local>\n&lt;remote uuid=\"73ad72d2-122f-4faf-9e56-a8cb90f6b8dd\">\n  &lt;enabled>1&lt;\/enabled>\n  &lt;connection>42820841-7655-4c82-ba28-69819916dcdb&lt;\/connection>\n  &lt;round>0&lt;\/round>\n  &lt;auth>psk&lt;\/auth>\n  &lt;id>2.2.2.2&lt;\/id>\n  &lt;eap_id\/>\n  &lt;groups\/>\n  &lt;certs\/>\n  &lt;cacerts\/>\n  &lt;pubkeys\/>\n  &lt;description>RemoteID&lt;\/description>\n&lt;\/remote>\n&lt;child uuid=\"c7fad1f8-a4e8-46bb-9298-ce7af5bedb6a\">\n  &lt;enabled>1&lt;\/enabled>\n  &lt;connection>42820841-7655-4c82-ba28-69819916dcdb&lt;\/connection>\n  &lt;reqid\/>\n  &lt;esp_proposals>aes256-sha256-modp2048&lt;\/esp_proposals>\n  &lt;sha256_96>0&lt;\/sha256_96>\n  &lt;start_action>start&lt;\/start_action>\n  &lt;close_action>none&lt;\/close_action>\n  &lt;dpd_action>clear&lt;\/dpd_action>\n  &lt;mode>tunnel&lt;\/mode>\n  &lt;policies>1&lt;\/policies>\n  &lt;local_ts>172.40.1.0\/24&lt;\/local_ts>\n  &lt;remote_ts>192.168.13.0\/24&lt;\/remote_ts>\n  &lt;rekey_time>3600&lt;\/rekey_time>\n  &lt;description\/>\n&lt;\/child><\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Example IP of OpnSense : 1.1.1.1 Local IP of OpenSense : 172.40.1.0\/24 Example IP of Forti : 2.2.2.2 Local IP of Forti : 192.168.13.0\/24 Forti Config ( [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-9196","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/9196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=9196"}],"version-history":[{"count":2,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/9196\/revisions"}],"predecessor-version":[{"id":9203,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/9196\/revisions\/9203"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=9196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=9196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=9196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}