DemianJacome
Contributor
Contributor

VPN DO NOT ESTABLISH BETWEEN VELOCLOUD GATEWAY AND FORTIGATE

Hi guys,

I have a problem with IpSec VPN between Velocloud gateway and Fortigate (VM fortigate on OCI, fortigate 200E, 80E, and 500E appliance).

In both cases the VPN isn't established correctly. Do you have the same problem or something similar?

In the case of VPN between Velocloud Gateway and Fortigate VM there is a mismatch with the SPI parameter

Labels (3)
Reply
0 Kudos
khirom
Enthusiast
Enthusiast

Hi,

I have never used Fortigate FW with VMware SD-WAN.

It may be  PFS setting.

Have you tried "no PFS" setting?

Reply
0 Kudos
TalalTayyaroğlu
Enthusiast
Enthusiast

Good day,

I have just had the same issue but when connecting to a Cisco ISR.

I have since resolved this but you will need to know the limitations:

The setup is limited to what the Gateway supports. For example, to connect to a Cisco ISR, you are limited to using a Tunnel interface routing method, and cannot use a Crypto ACL. Also in my case, I am stuck with IKEv1, and with SHA hashing. SHA-256 and above are not supported.

Trying to connect a Cisco ISR router to the Gateway using the "Generic IKEv1/2 Router" method has failed so far. 

What option did you use to connect to your Fortigate? I could not spot such an option?

Can you share the configuration on your Fortigate and on Orchestrator?

I might be able to spot some discrepancies. 

regards,

Talal

Reply
0 Kudos
khirom
Enthusiast
Enthusiast

Hi,
I have successfully configured a VPN between Fortigate and VMware SD-WAN Gateway.
Fortigate interface had a public IP address.
I have not tested it in a NAT environment.
Initially, I tried using AES128, SHA-1, and DH2.
After confirming the VPN was established, I switched to stronger parameters.
After setting NSD in the profile, the VPN was established.
I think VMware SD-WAN Gateway is the responder and Fortigate is the Initiator.

Reply
0 Kudos