Skip to main content

VPN Site-to-Site configuration with Fortigate

Prerequisites

Ensure the following conditions are met before starting:

  • VPN Site-to-Site has been created on FPT Cloud Portal.
  • Fortigate is installed, enabled, and licensed on the customer side.
  • Fortigate has been configured with LAN and WAN IP addresses.

Step 1: Configure VPN Site-to-Site on FPT Cloud Portal

Create a Customer Gateway and a VPN Connection for the Fortigate device on the FPT Cloud Portal. For detailed steps, see Create VPN connection.

Step 2: Configure IPsec on Fortigate

  1. Log in to the Fortigate web interface.

Fortigate login

  1. Select IPsec Wizard.

IPsec Wizard

  1. Go to IPsec Tunnels:
    • Enter the FPT Cloud IP address from Step 1.
    • Select the WAN interface (if multiple WAN interfaces exist, specify the one to use).

IPsec Tunnel config

Check the connection status on FPT Smart Cloud Portal.

Connection status

  1. Enable Local Gateway and select Primary IP.

Local Gateway

  1. Set the Method to Pre-shared Key and enter the same key as in Step 1.

Pre-shared key

note

If the customer setup is behind NAT, configure as shown below and contact L3-FPT Smart Cloud for support.

NAT config

  1. Configure Phase 1.

Phase 1

If NAT is not used, ensure that NAT mode is disabled.

  1. Configure Phase 2. Set the Local IP to the customer network range.

Phase 2

Step 3: Configure firewall and routing on Fortigate

Set the firewall to Allow All for both incoming and outgoing traffic.

From FPT Cloud to Fortigate:

FPT to Fortigate

From Fortigate to FPT Cloud:

Fortigate to FPT

Connection successfully established:

Connection established

Configure routing with the Destination set to the FPT Cloud network (e.g., 172.30.205.0/255.255.255.0) and Interface set to the IPsec tunnel created earlier.

Routing config

You can now open a terminal to test network connectivity using ping.

See also