Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Site-to-Site VPN between OpenSense and Fortigate
« previous
next »
Print
Pages: [
1
]
Author
Topic: Site-to-Site VPN between OpenSense and Fortigate (Read 2898 times)
Member1
Newbie
Posts: 1
Karma: 0
Site-to-Site VPN between OpenSense and Fortigate
«
on:
October 26, 2023, 04:01:41 pm »
Hi,
I want to create a Site-to-Site VPN IPsec between Opensense and ForiGate. Therefore, i have some questions:
- Is it possible to create S2S between Opensense and FGATE?
- If yes, how can i block the communication that are come from the Fgate?, my goal is to allow the lan subnet on opensense (192.168.1.0/24) to communicating with lan-subnet on Fgate (10.10.1.0/24), but not vice versa.
Regards
Logged
Monviech (Cedrik)
Global Moderator
Hero Member
Posts: 1601
Karma: 176
Re: Site-to-Site VPN between OpenSense and Fortigate
«
Reply #1 on:
October 26, 2023, 04:30:48 pm »
IPsec is a protocol that is not vendor specific. As long as the devices adhere to the IPsec standard, a tunnel can be established.
- An IPsec tunnel between an OPNsense (which uses Strongswan as IPsec implementation) and FortiGate (which use their own closed source IPsec implementation) is possible, as long as both sides use the same settings.
- Communication into the LAN Subnet of the OPNsense can be blocked with filter rules (Firewall rules). Creating an IPsec tunnel creates a virtual interface group called "IPsec" on which filter rules can be defined in the GUI. As long as no pass rules are set, all incoming traffic is denied.
- Communication from the LAN Subnet to the Fortigate Subnet can be allowed by setting pass filter rules with the destination to the Fortigate Subnet on the "LAN" firewall rules.
Logged
Hardware:
DEC740
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Site-to-Site VPN between OpenSense and Fortigate