IPsec VPN Connectivity (NSF to Fortigate)

libaobillie0629 Lv1Posted Apr-15-2025 15:13

Last edited by libaobillie0629 2025-Apr-15 15:14.

Existing Firewall: Fortinet
No. Of branches: 25
HQ Firewall License: Expired

I have a client that has a requirement of SDWAN. I already replace their exisitng Fortinet HQ Firewall to an NSF Firewall. Is it possible to connect our NSF firewall (HQ) to the branches via IPSEC (fortinet fw)??
What will be the problem or challenges if it is not possible? Let me know any recommendation for this one. Thank you in advance.

Enrico Vanzetto has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Hi, yes it's possible. You have to find what ipsec parameters on both phase are suitable to NSF and Fortinet branch firewalls. I suggest you to try reconfigure on HQ NSF an ipsec with the same parameters pn both phase that are on fortinet branch device. You have to change passphrase on ipsec phase1 for security reasons.
Is this answer helpful?
Ayra Posted Apr-19-2025 13:50
  
Hello.  Yes, that is possible.  In all phases, you must determine which ipsec parameters are appropriate for Fortinet branch firewalls and NSF firewalls.  In my opinion, try adjusting the HQ NSF and IPSec with the same parameters on both phases of the Fortinet branch device.  For security reasons, you must change your IPsec phase 1 passphrase.
Newbie617866 Posted Apr-19-2025 00:46
  
Thanks for sharing
Zonger Lv5Posted Apr-18-2025 19:30
  
Yes, it is possible to connect your NSF firewall at HQ to the 25 branch Fortinet firewalls via IPSec VPN as IPSec is a standard protocol and both NSF and Fortinet support it.
AR Lv2Posted Apr-15-2025 17:40
  
Hello.
Indeed, that is feasible.  You must determine which ipsec parameters on both phases are appropriate for Fortinet branch firewalls and NSF firewalls.  Try reconfiguring the HQ NSF and ipsec with the identical parameters on both phases of the fortinet branch device, in my opinion.  For security reasons, you must modify your IPsec phase 1 passphrase.
Saddam Hussain Lv1Posted Apr-15-2025 15:53
  
Thank you for sharing

I Can Help:

Change

Moderator on This Board

1
148
3

Started Topics

Followers

Follow

917
183
94

Started Topics

Followers

Follow

Board Leaders