Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
youcef_guessad
New Contributor

Policy based ip sec VPN

Hello,

 

I have fortios 5.6.2 and I would like to configure tunnel VPN with policy based ipsec but, I don't have a chose between firewall and vpn policy.

 

find attached my capture.

 

Thank you for your help.

4 REPLIES 4
null
New Contributor

I've got the same problem. FW 5.6.3, NGFW, central SNAT. I want to use policy based ipsec because i need a lot of nat, so it would be easier to use nat in ipsec policy not in central snat table. Is policy based ipsec obsolete?

Pete_Benac

To do policy based VPN the tunnel cannot be created as an interface tunnel.    Considering the tunnel is not showing up here I am assuming when you created Phase 1 of the tunnel you didn't unselect the Interface Selection.

 

 

 

 

rwpatterson
Valued Contributor III

You can still NAT an interface based IPSec tunnel (in both directions if needed...), you just need to create an IP pool and use that in the policy handling the IPSec tunnel. This is far easier (to me) than d*cking with the old policy based process.

 

My two cents

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
emnoc
Esteemed Contributor III

And to add ,  a rt-based vpn has a interface so you can do anything with it like a vlan interface

 

 

 set a inerface egress SNAT ( over load  masquerading )

 set a  DNAT against it

 management allowaccess

etc....

 

I prefer  rt-based over policy-base

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors