Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Centrocito
New Contributor

UTM throught IPSEC VPN

Hello community 6

 

So my question is this:

 

If I have a branch office connected via IPSEC VPN site-to-site, do I need UTM licence on my 60D in the branch office or can I filter everything through my 100D in the main office?

 

Thanks

2 Solutions
rwpatterson
Valued Contributor III

You can filter through the main 100D. Two drawbacks:

1) All the traffic has to go through that Internet pipe twice

2) If the 100D goes south (or that Internet connection), any branch being filtered through it is effectively down

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

View solution in original post

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
rwpatterson
Valued Contributor III

Apply them to the policy vpn to Internet.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

View solution in original post

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
5 REPLIES 5
rwpatterson
Valued Contributor III

You can filter through the main 100D. Two drawbacks:

1) All the traffic has to go through that Internet pipe twice

2) If the 100D goes south (or that Internet connection), any branch being filtered through it is effectively down

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Centrocito

rwpatterson wrote:

You can filter through the main 100D. Two drawbacks:

1) All the traffic has to go through that Internet pipe twice

2) If the 100D goes south (or that Internet connection), any branch being filtered through it is effectively down

If I create the VPN by default it applies these settings we are talking about or do I need to configure anything additional??

rwpatterson
Valued Contributor III

Apply them to the policy vpn to Internet.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Centrocito

rwpatterson wrote:

Apply them to the policy vpn to Internet.

Thanks for the fast response and accuracy !

rwpatterson
Valued Contributor III

Rare moment of slow time here....

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors