<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN DO NOT ESTABLISH BETWEEN VELOCLOUD GATEWAY AND FORTIGATE in VeloCloud Discussions</title>
    <link>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2985905#M166</link>
    <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;I have just had the same issue but when connecting to a Cisco ISR.&lt;/P&gt;&lt;P&gt;I have since resolved this but you will need to know the limitations:&lt;/P&gt;&lt;P&gt;The setup is limited to what the Gateway supports. For example, to connect to a Cisco ISR, you are limited to using a Tunnel interface routing method, and cannot use a Crypto ACL. Also in my case, I am stuck with IKEv1, and with SHA hashing. SHA-256 and above are not supported.&lt;/P&gt;&lt;P&gt;Trying to connect a Cisco ISR router to the Gateway using the &lt;EM&gt;&lt;U&gt;"Generic IKEv1/2 Router"&lt;/U&gt;&lt;/EM&gt; method has failed so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What option did you use to connect to your Fortigate? I could not spot such an option?&lt;/P&gt;&lt;P&gt;Can you share the configuration on your Fortigate and on Orchestrator?&lt;/P&gt;&lt;P&gt;I might be able to spot some discrepancies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Talal&lt;/P&gt;</description>
    <pubDate>Fri, 08 Sep 2023 19:40:20 GMT</pubDate>
    <dc:creator>TalalTayyaroğlu</dc:creator>
    <dc:date>2023-09-08T19:40:20Z</dc:date>
    <item>
      <title>VPN DO NOT ESTABLISH BETWEEN VELOCLOUD GATEWAY AND FORTIGATE</title>
      <link>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2984290#M157</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I have a problem with IpSec VPN between Velocloud gateway and Fortigate (VM fortigate on OCI, fortigate 200E, 80E, and 500E appliance).&lt;/P&gt;&lt;P&gt;In both cases the VPN isn't established correctly.&amp;nbsp;Do you have the same problem or something similar?&lt;/P&gt;&lt;P&gt;In the case of VPN between Velocloud Gateway and Fortigate VM there is a mismatch with the SPI parameter&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 15:03:04 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2984290#M157</guid>
      <dc:creator>DemianJacome</dc:creator>
      <dc:date>2023-08-28T15:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DO NOT ESTABLISH BETWEEN VELOCLOUD GATEWAY AND FORTIGATE</title>
      <link>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2984420#M158</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have never used Fortigate FW with VMware SD-WAN.&lt;/P&gt;&lt;P&gt;It may be&amp;nbsp; PFS setting.&lt;/P&gt;&lt;P&gt;Have you tried "no PFS" setting?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 12:35:09 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2984420#M158</guid>
      <dc:creator>khirom</dc:creator>
      <dc:date>2023-08-29T12:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DO NOT ESTABLISH BETWEEN VELOCLOUD GATEWAY AND FORTIGATE</title>
      <link>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2985905#M166</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;I have just had the same issue but when connecting to a Cisco ISR.&lt;/P&gt;&lt;P&gt;I have since resolved this but you will need to know the limitations:&lt;/P&gt;&lt;P&gt;The setup is limited to what the Gateway supports. For example, to connect to a Cisco ISR, you are limited to using a Tunnel interface routing method, and cannot use a Crypto ACL. Also in my case, I am stuck with IKEv1, and with SHA hashing. SHA-256 and above are not supported.&lt;/P&gt;&lt;P&gt;Trying to connect a Cisco ISR router to the Gateway using the &lt;EM&gt;&lt;U&gt;"Generic IKEv1/2 Router"&lt;/U&gt;&lt;/EM&gt; method has failed so far.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What option did you use to connect to your Fortigate? I could not spot such an option?&lt;/P&gt;&lt;P&gt;Can you share the configuration on your Fortigate and on Orchestrator?&lt;/P&gt;&lt;P&gt;I might be able to spot some discrepancies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Talal&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 19:40:20 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2985905#M166</guid>
      <dc:creator>TalalTayyaroğlu</dc:creator>
      <dc:date>2023-09-08T19:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DO NOT ESTABLISH BETWEEN VELOCLOUD GATEWAY AND FORTIGATE</title>
      <link>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2992003#M208</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I have successfully configured a VPN between Fortigate and VMware SD-WAN Gateway.&lt;BR /&gt;Fortigate interface had a public IP address.&lt;BR /&gt;I have not tested it in a NAT environment.&lt;BR /&gt;Initially, I tried using AES128, SHA-1, and DH2.&lt;BR /&gt;After confirming the VPN was established, I switched to stronger parameters.&lt;BR /&gt;After setting NSD in the profile, the VPN was established.&lt;BR /&gt;I think VMware SD-WAN Gateway is the responder and Fortigate is the Initiator.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Oct 2023 05:24:29 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VeloCloud-Discussions/VPN-DO-NOT-ESTABLISH-BETWEEN-VELOCLOUD-GATEWAY-AND-FORTIGATE/m-p/2992003#M208</guid>
      <dc:creator>khirom</dc:creator>
      <dc:date>2023-10-21T05:24:29Z</dc:date>
    </item>
  </channel>
</rss>

