Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (2024)

Introduction

I am gonna show you, step by step how to configure a Site-to-Site VPN between a FortiGate Firewall and Microsoft Azure. The following steps describe how to configure a site-to-site VPN tunnel.

  • Creating the Microsoft Azure virtual network
  • Creating the Microsoft Azure virtual network gateway
  • Creating the Microsoft Azure Local network gateway
  • Creating the VPN Connection
  • Configuring the FortiGate tunnel
  • Creating the FortiGate firewall addresses
  • Creating the FortiGate firewall policies
  • Connectivity Test
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (1)

Create the Virtual Networks

Step 1: Let’s go to the Microsoft Azure portal. Search for Virtual Network and click on the search result Virtual Networks.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (2)

Step 2: Click on the Create button on the Virtual Network step.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (3)

Step 3: On the Create virtual network step, select the Basics tab and then provide the below details as your wish.

  • Subscription: Select your active subscription.
  • Resource group: Select an existing resource group or we can create a new resource group.
  • Name: We have to provide a meaningful name for the virtual network.
  • Region: Select the nearest Region.

Once you filled in, Click on the Next: IP Addresses button to navigate to the IP Addresses step.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (4)

Step 4: In this step, We need to provide the virtual network address space, specified as one or more address prefixes in CIDR 10.0.0.0/24.

Add Subnet: The subnets address range in CIDR 10.0.0.0/24. It should be contained by the address space of the virtual network.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (5)

Step 5: Now, it will validate all the data entered by me and show you the Validation passed. Finally, we have to click on the Create button to create the Virtual network.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (6)

Step 6: In this step, it will show you “Your deployment is complete”. Then click on the Go to resource button to navigate to the virtual network interface.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (7)

Create the Virtual Network Gateway

Step 7: Let’s go to the Microsoft Azure portal. Search for Virtual network gateway and click on the search result Virtual network gateway.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (8)

Step 8: On the Virtual network gateways interface, Click Create.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (9)

Step 9: On the Create Virtual network gateway step, select the Basics tab and then provide the below details as your wish.

  • Name: We have to provide a name that matches the name of our new virtual network.
  • Gateway type: Select VPN.
  • VPN type: Select Route-based VPN.
  • SKU: Select Basic, as it fits the requirements of most SMBs (Server Message Blocks).
  • Virtual network: Choose the Virtual Network that we created.
  • Public IP address: Create a new public IP address, give it a meaningful name.

Click on Review + Create. (The creation of the virtual network gateway will take some time to complete).

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (10)
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (11)

Step 10: Now, it will validate all the data entered by me and show you the Validation passed. Finally, we have to click on the Create button to create the virtual network gateway.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (12)

Step 11: In this step, it will show you “Your deployment is complete”.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (13)

Create the Local Network Gateway

We should create another interface to represent Our (Newhelptech Datacenter) local on-premises network. Microsoft Azure knows your location, and what is behind our (Newhelptech Datacenter) firewall.

Step 12: Let’s go to the Microsoft Azure portal. Search for Local Network Gateway and click on the search result Local Network Gateway.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (14)

Step 13: Click on the Create button on the Local Network Gateway step.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (15)

Step 14: In this Step, Create a local gateway that represents our (NewHelptech Datacenter) local network firewall.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (16)

Step 15: Now, it will validate all the data entered by me and show you the Validation passed. Finally, we have to click on the Create button.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (17)

Step 16: In this step, it will show you “Your deployment is complete”.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (18)

Create a Site-to-Site VPN between Azure to FortiGate

Step 16: Let’s get into the Virtual network gateways interface then click on the Connections tab after that click on Add button. We have to provide the below details as your wish

  • Name: Provide a name related to the Azure Virtual network that you are creating.
  • Connection type: From the drop-down, select Site-to-Site (IPSec).
  • Local network gateway: Select the Local network gateway that we created.
  • Shared key (PSK): Provide a complex string and save it securely. You must provide this key on your on-premises (Newhelptech Datacenter) firewall.

After entering these details, click on the OK button.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (19)
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (20)
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (21)
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (22)

On-Prem FortiGate Firewall (Newhelptech Datacenter) configuration

Step 17: To create VPN Tunnels go to the VPN tab then select IPSec Tunnels then click on Create New.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (23)
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (24)

Step 18: The VPN Create Wizard table once appears and fills in the following configuration information.

  • Remote IP address – public IP address of the Azure virtual network gateway. (104.208.74.7)
  • Outgoing interface – port4 (WAN)
  • Authentication method – Pre-shared key (From Azure Connection)

Click on Next.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (25)

Step 19: The VPN Create Wizard table Policy and & Routing appears and fills in the following configuration information.

  • Local interface: port1 (We should select our LAN connecting interface)
  • Local Address: Select Subnet and enter Fortinet’s 192.168.2.0/24 LAN subnet.
  • Remote Address (Azure): Select Subnet and enter Azure 10.1.0.0/24 Backend subnet.

Click on Create.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (26)

Step 20: Now, Site to Site VPN has been created on FortiGate firewall.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (27)

Step 21: Please see the below screenshots for your reference of configuring the parameters FortiGate firewall Site to Site VPN between NewHelptech Datacenter to Azure.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (28)
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (29)

Step 22: On the Fortinet NewHelpTech Datacenter firewall and Azure VPN Connection , we can check whether the VPN connection is successful or not by going to Monitor then clicking on IPSec Monitor.

We will see that the VPN connection has been established and there is Incoming Data and Outgoing Data traffic.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (30)
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (31)

Connectivity Test

We established the connection. Let us ping from NewHelpTech DataCneter to Azure VM 10.1.0.4.

Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (32)

I would greatly appreciate it if you kindly give some feedback on my articles. It will be a booster 🤝

Happy New Year 2022

  • Categories
  • Microsoft Azure
Step by Step How to Configure Site-to-Site VPN Microsoft Azure to FortiGate (2024)
Top Articles
Goodreads
Easily DIY Fence Installation with These 5 Tips from the Pros
Chris Provost Daughter Addie
Txtvrfy Sheridan Wy
The Best Classes in WoW War Within - Best Class in 11.0.2 | Dving Guides
Wfin Local News
Delectable Birthday Dyes
Weekly Math Review Q4 3
Inside California's brutal underground market for puppies: Neglected dogs, deceived owners, big profits
Diablo 3 Metascore
Betonnen afdekplaten (schoorsteenplaten) ter voorkoming van lekkage schoorsteen. - HeBlad
RBT Exam: What to Expect
House Party 2023 Showtimes Near Marcus North Shore Cinema
Https://Store-Kronos.kohls.com/Wfc
Pricelinerewardsvisa Com Activate
Does Breckie Hill Have An Only Fans – Repeat Replay
Evil Dead Rise - Everything You Need To Know
Unforeseen Drama: The Tower of Terror’s Mysterious Closure at Walt Disney World
Dallas Craigslist Org Dallas
Miltank Gamepress
Directions To Cvs Pharmacy
پنل کاربری سایت همسریابی هلو
Milwaukee Nickname Crossword Clue
Geico Car Insurance Review 2024
Is Light Raid Hard
Enduring Word John 15
O'reilly's In Monroe Georgia
Cvs Sport Physicals
Chicago Pd Rotten Tomatoes
Federal Student Aid
Elgin Il Building Department
Weapons Storehouse Nyt Crossword
Hingham Police Scanner Wicked Local
Bella Thorne Bikini Uncensored
Restored Republic May 14 2023
Busted Newspaper Campbell County KY Arrests
Bob And Jeff's Monticello Fl
Ig Weekend Dow
Bunkr Public Albums
Vindy.com Obituaries
Garland County Mugshots Today
Reli Stocktwits
Killer Intelligence Center Download
Wolf Of Wallstreet 123 Movies
Cvs Coit And Alpha
Page 5747 – Christianity Today
Oak Hill, Blue Owl Lead Record Finastra Private Credit Loan
Blog Pch
M Life Insider
Latest Posts
Article information

Author: Geoffrey Lueilwitz

Last Updated:

Views: 5386

Rating: 5 / 5 (80 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Geoffrey Lueilwitz

Birthday: 1997-03-23

Address: 74183 Thomas Course, Port Micheal, OK 55446-1529

Phone: +13408645881558

Job: Global Representative

Hobby: Sailing, Vehicle restoration, Rowing, Ghost hunting, Scrapbooking, Rugby, Board sports

Introduction: My name is Geoffrey Lueilwitz, I am a zealous, encouraging, sparkling, enchanting, graceful, faithful, nice person who loves writing and wants to share my knowledge and understanding with you.