如果你用VPN, FORTIGATE去FORTIGATE用內建TEMPLATE就能沒腦建好了
如果你不用VPN而是用LAN直連
假設
(192.168.0.0/24) A Port 2 - Fortigate A - A Port 3 (172.16.0.1)----
------(172.16.0.254) B Port 3 - Fortigate B - B Port 2 (192.168.1.0/24)
Fortigate A setting:
Policy: From Port 2,3 to Port 2,3 Any Any Allow, No NAT
Static Route: Network 192.168.1.0/24, Gateway: 172.16.0.254
Fortigate B setting:
Policy: From Port 2,3 to Port 2,3 Any Any Allow, No NAT
Static Route: Network 192.168.0.0/24, Gateway: 172.16.0.1
VPN+1
提供官方文件:
Site-to-site IPsec VPN with two FortiGates
http://cookbook.fortinet.com/site-site-ipsec-vpn-two-fortigates-56/
GOOGLE一下,
有不少前輩有分享 Fortigate site to site VPN.
FW1的哪個interface接 Sauce(醬汁)?
FW1的哪個interface接FW2
FW2的哪個interface接FW1
FW1的哪個interface接 destroy(破壞)?
沒寫出來,規則與方法不同!
如果Source 接 FW1的LAN
FW1的WAN 接FW2 LAN
FW2的LAN 接 FW1 WAN
FW2的WAN 接 Destation
那規則就是LAN to WAN (Destation IP) any port