Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPsec VPN to Fortinet Firewall

    Scheduled Pinned Locked Moved IPsec
    3 Posts 2 Posters 9.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      talbotc
      last edited by

      Hello,
      Does anyone have experience with pfSense to Fortinet IPsec VPN.
      We have experience with VPN concepts and other 3rd party products establishing VPNs to the Fortinet but, no experience with pfSense.

      We have confirmed the usual suspects… aggresive, shared key, etc and matched configuration parameters but VPN is failing to establish.
      Fortinet subnet is 10.0.0.0/24
      pfSense subnet is 10.0.1.0/28

      Any help or insight where to look or how to debug pfSense would be greatly appreciated.

      1 Reply Last reply Reply Quote 0
      • P
        psylo
        last edited by

        First, where are the public IP? Directly on the pfSense and the Fortinet or not? In some words, is there any NAT device between them? If it's the case, I think NAT-T (Nat traversal) is supported only in pfSense 1.3 (I don't know if it's by Fortinet). If NAT-T is not supported, don't go further…

        If NAT-T is supported, you have to check if port UDP/4500 and UDP/500 are redirected on your firewall (pfSens and Fortinet).

        Last, you can dump packets (with tcpdump - man page available on Internet) on the pfSense outside interface to see if packet are arriving from Fortinet...

        Hope ths helps.

        1 Reply Last reply Reply Quote 0
        • T
          talbotc
          last edited by

          I was able to get this working.
          I had to configure local and remote subnets in the fortinet phase2 vpn definition.

          Otherwise, it came up instantly.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.