Connecting two geographically distributed corporate offices securely over the public Internet requires a resilient, hardware-accelerated IPsec Site-to-Site VPN tunnel. On modern FortiGate firewalls running FortiOS 7.2 or 7.4, this can be achieved efficiently using either the graphical VPN Wizard or FortiGate CLI for custom routing parameters.
Prerequisites for IPsec Tunnel Setup
Before initiating the phase 1 and phase 2 proposals, ensure you have gathered the following parameters from both HQ and Branch firewalls:
- Static Public IP Addresses: WAN interface IP for both FortiGate gateways.
- Pre-Shared Key (PSK): A high-entropy alphanumeric string (minimum 32 characters).
- Local & Remote Subnets: e.g., HQ (192.168.10.0/24) and Branch (192.168.20.0/24).
- Encryption Proposals: Phase 1 (AES-256, SHA-256, DH Group 14) and Phase 2 (AES-GCM-256, PFS enabled).
Step 1: Create Phase 1 Interface via FortiGate CLI
Connect via SSH or console to the primary FortiGate firewall and execute the following configuration:
config vpn ipsec phase1-interface
edit "HQ-to-Branch-VPN"
set interface "wan1"
set peertype any
set net-device disable
set proposal aes256-sha256
set remote-gw 203.0.113.50
set psksecret "YourSuperComplexPresharedKey987!"
next
end
Step 2: Configure Phase 2 Selector & Traffic Policies
Next, define the internal subnet selectors so the firewall knows which packets should be encapsulated into the IPsec tunnel:
config vpn ipsec phase2-interface
edit "HQ-Branch-P2"
set phase1name "HQ-to-Branch-VPN"
set proposal aes256gcm
set src-subnet 192.168.10.0 255.255.255.0
set dst-subnet 192.168.20.0 255.255.255.0
set auto-negotiate enable
next
end
Step 3: Verification & Diagnostics
To verify the phase 1 SA (Security Association) and phase 2 tunnel state, run the following diagnostic commands:
diagnose vpn ike gateway list name "HQ-to-Branch-VPN"
diagnose vpn tunnel list
When the status displays phase=1, status=negotiated and phase=2, status=installed, your secure tunnel is fully operational with zero packet loss.