Network Security

How to Configure FortiGate Firewall IPsec Site-to-Site VPN (CLI & GUI)

By • • 2 min read
How to Configure FortiGate Firewall IPsec Site-to-Site VPN (CLI & GUI)

Table of Contents

Connecting two geographically distributed corporate offices securely over the public Internet requires a resilient, hardware-accelerated IPsec Site-to-Site VPN tunnel. On modern FortiGate firewalls running FortiOS 7.2 or 7.4, this can be achieved efficiently using either the graphical VPN Wizard or FortiGate CLI for custom routing parameters.

Prerequisites for IPsec Tunnel Setup

Before initiating the phase 1 and phase 2 proposals, ensure you have gathered the following parameters from both HQ and Branch firewalls:

  • Static Public IP Addresses: WAN interface IP for both FortiGate gateways.
  • Pre-Shared Key (PSK): A high-entropy alphanumeric string (minimum 32 characters).
  • Local & Remote Subnets: e.g., HQ (192.168.10.0/24) and Branch (192.168.20.0/24).
  • Encryption Proposals: Phase 1 (AES-256, SHA-256, DH Group 14) and Phase 2 (AES-GCM-256, PFS enabled).

Step 1: Create Phase 1 Interface via FortiGate CLI

Connect via SSH or console to the primary FortiGate firewall and execute the following configuration:

config vpn ipsec phase1-interface
    edit "HQ-to-Branch-VPN"
        set interface "wan1"
        set peertype any
        set net-device disable
        set proposal aes256-sha256
        set remote-gw 203.0.113.50
        set psksecret "YourSuperComplexPresharedKey987!"
    next
end

Step 2: Configure Phase 2 Selector & Traffic Policies

Next, define the internal subnet selectors so the firewall knows which packets should be encapsulated into the IPsec tunnel:

config vpn ipsec phase2-interface
    edit "HQ-Branch-P2"
        set phase1name "HQ-to-Branch-VPN"
        set proposal aes256gcm
        set src-subnet 192.168.10.0 255.255.255.0
        set dst-subnet 192.168.20.0 255.255.255.0
        set auto-negotiate enable
    next
end

Step 3: Verification & Diagnostics

To verify the phase 1 SA (Security Association) and phase 2 tunnel state, run the following diagnostic commands:

diagnose vpn ike gateway list name "HQ-to-Branch-VPN"
diagnose vpn tunnel list

When the status displays phase=1, status=negotiated and phase=2, status=installed, your secure tunnel is fully operational with zero packet loss.

manircmt

Technical Writer & Systems Specialist

Dedicated to solving enterprise IT, cloud administration, and networking problems with straightforward, practical guides.