Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sawtom
New Contributor III

Any additional settings for FortiGate-VM on GCP?

Hi,

I am testing on GCP, to create VPN between FortiGate-VM and the on-prem router.

 

It is connected over Cloud Interconnect and BGP for Cloud Router.

The routes are correctly advertised(including FG-VM and the on-prem router), but the ping between that two hosts fails.

 

I want the next hop of FG-VM to connect to Cloud Router, but it seems to connect to the Internet gateway.

Are there any additional settings to set FG's next hop to Cloud Router?

 

Of course Cloud Router and FG-VM belong to the same VPC network/VPC network subnet.

Please give me some ideas.

 

regards, 

FortiGate FortiGate Cloud 

Sawtom
Sawtom
8 REPLIES 8
Mitesh
New Contributor III

Hi Sawtom,

 

Did you change the default route in the VPC.

 

By default when you create VPC default route pointing towards internet gateway, which needs to b deleted & create new default route which point towards Forti-VM interface IP.

Sawtom
New Contributor III

Hi @Mitesh 
Thank you for your advice.

 

I tried some but it's still not working.
When I was creating a route, I set the priority as the new rule gets prior to the default one.
*Instead of deleting the default route which you explain may be used by other instances.

 

Then I set the next hop as "Default internet gateway", "Specify an instance" and "Specify IP address of an instance".
And "Specify VPN tunnel", it shows nothing.

 

I will keep doing.

 

regards,

Sawtom
Sawtom
Mitesh
New Contributor III

Hi Sawtom,

 

Can you please share architecture diagram, which will give us better understanding of problem statement. 

Sawtom
New Contributor III

Hi @Mitesh ,

I would share the architecture here.

Actually I am not sure any more about details of the on-prem side.
Is this helpful for you?


■Physical / Network
Physical:
    VPN/BGP Router --- |On-prem| --- (Service Provider) --- |Google Cloud| --- Cloud Router --- FortiGate-VM
Network (on GCP):
    (Service Provider) --- Cloud Router --- (VPC-NW-A-subnet) --- [nic0]FortiGate-VM

■Logical
Underlay:
    BGP --- |On-prem| --- (Service Provider) --- |GCP| --- BGP
Overlay:
    VPN tunnel --- (BGP) --- |On-prem| --- (Service Provider) --- |GCP| --- (BGP) --- VPN tunnel


regards,

Sawtom
Sawtom
Mitesh
New Contributor III

Hi Sawtom,

 

Based on your input i have drawn architecture diagram, is my understanding is right.

 

Cloud_HA_VPN_to_Remote_Device-VPN.jpg

Sawtom
New Contributor III

Hi @Mitesh 
Yes, almost correct: I would like to compose it without Cloud VPN/HA VPN.(This is a test so please understand that.)
To keep VPN tunnel up, I would see 2 patterns;

1.using Cloud VPN(= HA VPN)

2.using FG-VM


regards,

Sawtom
Sawtom
Mitesh
New Contributor III

Hi Sawtom,

 

Are you using Cloud VPN or NGFW for IPSec tunnel ?

 

Sawtom
New Contributor III

Hi @Mitesh ,

I am using NGFW.(but now actually the tunnel is not up...)

Sawtom
Sawtom
Labels
Top Kudoed Authors