{"id":1228,"date":"2026-01-23T16:06:30","date_gmt":"2026-01-23T21:06:30","guid":{"rendered":"https:\/\/pressbooks.bccampus.ca\/paloalto\/?post_type=chapter&#038;p=1228"},"modified":"2026-02-19T15:36:20","modified_gmt":"2026-02-19T20:36:20","slug":"site-to-site-vpn-cisco-palo-alto","status":"publish","type":"chapter","link":"https:\/\/pressbooks.bccampus.ca\/paloalto\/chapter\/site-to-site-vpn-cisco-palo-alto\/","title":{"raw":"3.4 Site to Site VPN PaloAlto, Cisco and FortiGate","rendered":"3.4 Site to Site VPN PaloAlto, Cisco and FortiGate"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\r\n<p class=\"textbox__title\">Learning Objectives<\/p>\r\n\r\n<\/header>\r\n<div class=\"textbox__content\">\r\n<ul>\r\n \t<li>Create a tunnel in Cisco router<\/li>\r\n \t<li>Create a tunnel in Palo Alto<\/li>\r\n \t<li>Connect a tunnel from Cisco router to Palo Alto<\/li>\r\n \t<li>Connect a FortiGate tunnel to Palo Alto<\/li>\r\n<\/ul>\r\n<\/div>\r\n<\/div>\r\n<div class=\"textbox shaded\">\r\n\r\n<strong>Scenario<\/strong>:\u00a0 We are going to do a site-to-site VPN from Cisco to Palo Alto and then expand it between FortiGate and Palo Alto.\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n[caption id=\"attachment_1232\" align=\"aligncenter\" width=\"790\"]<img class=\"wp-image-1232 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131201.png\" alt=\"\" width=\"790\" height=\"312\" \/> Figure 3.65: Main Scenario[\/caption]\r\n\r\n<div align=\"left\">\r\n<table style=\"width: 100%\"><caption>Table 3.16: Addressing Table<\/caption>\r\n<tbody>\r\n<tr>\r\n<td style=\"width: 38.1989%\"><strong>Device<\/strong><\/td>\r\n<td style=\"width: 61.7516%\"><strong>Configuration<\/strong><\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 38.1989%\">Palo Alto<\/td>\r\n<td style=\"width: 61.7516%\">Ethernet 1\/1: 10.10.10.2\/24 \u2013 Type: Layer3\r\n\r\nEthernet 1\/2: 192.168.10.1\/24 \u2013 Type: Layer3\r\n\r\nManagement: 192.168.0.1\/24\u2013 Type: Layer3<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 38.1989%\">Router (7200)<\/td>\r\n<td style=\"width: 61.7516%\">G1\/0: 10.10.10.1\/24\r\n\r\nG2\/0: 192.168.20.1\/24<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 38.1989%\">WebTerm-1<\/td>\r\n<td style=\"width: 61.7516%\">192.168.0.2\/24<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 38.1989%\">WebTerm-2<\/td>\r\n<td style=\"width: 61.7516%\">IPV4: 192.168.10.2\/24 \u00a0 GW: 192.168.10.1<\/td>\r\n<\/tr>\r\n<tr>\r\n<td style=\"width: 38.1989%\">WebTerm-3<\/td>\r\n<td style=\"width: 61.7516%\">IPV4: 192.168.20.2\/24 \u00a0 GW: 192.168.20.1<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n<h2>Zones<\/h2>\r\n<div align=\"left\">\r\n<table style=\"width: 100%;height: 54px\"><caption>Table 3.17: Zones<\/caption>\r\n<tbody>\r\n<tr style=\"height: 18px\">\r\n<td style=\"width: 409.625px;height: 18px\"><strong>Zones<\/strong><\/td>\r\n<td style=\"width: 567.688px;height: 18px\"><strong>Interface<\/strong><\/td>\r\n<\/tr>\r\n<tr style=\"height: 18px\">\r\n<td style=\"width: 409.625px;height: 18px\">VPN<\/td>\r\n<td style=\"width: 567.688px;height: 18px\">Ethernet 1 \/1<\/td>\r\n<\/tr>\r\n<tr style=\"height: 18px\">\r\n<td style=\"width: 409.625px;height: 18px\">Trust<\/td>\r\n<td style=\"width: 567.688px;height: 18px\">Ethernet 1 \/2<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<\/div>\r\n&nbsp;\r\n<h2><strong>Cisco<\/strong><\/h2>\r\n<ol>\r\n \t<li style=\"font-weight: 400\">First, configure the router with the following commands:<\/li>\r\n<\/ol>\r\n<div class=\"textbox\">\r\n<pre>ip access-list extended Crypto_Acl\r\npermit ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255\r\n\r\n\r\ncrypto isakmp policy 1\r\nencr aes\r\nhash md5\r\nauthentication pre-share\r\ngroup 5\r\n\r\n\r\ncrypto isakmp key cisco123 address 10.10.10.2\r\ncrypto ipsec transform-set TSET esp-aes esp-sha-hmac\r\n\r\n\r\n\r\ncrypto map CMAP 10 ipsec-isakmp\r\nset peer 10.10.10.2\r\nset transform-set TSET\r\nmatch address Crypto_Acl\r\n\r\n\r\ninterface Gi1\/0\r\ncrypto map CMAP\r\n\r\nip route 0.0.0.0 0.0.0.0 10.10.10.2<\/pre>\r\n&nbsp;\r\n\r\n<\/div>\r\n<h2>Palo Alto<\/h2>\r\n<ol>\r\n \t<li style=\"font-weight: 400\">Create a tunnel and assign the tunnel to VPN Zone<\/li>\r\n<\/ol>\r\n[caption id=\"attachment_1266\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-1266 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905.png\" alt=\"Figure 3.66: create a tunnel\" width=\"1026\" height=\"824\" \/> Figure 3.66: create a tunnel[\/caption]\r\n\r\n2. Create a static route with following information:\r\n<div class=\"textbox\">\r\n\r\nDestination Address: 192.168.20.0\/24\r\n\r\nInterface: tunnel1\r\n\r\nNext Hope: none\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_1269\" align=\"aligncenter\" width=\"1023\"]<img class=\"wp-image-1269 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131936.png\" alt=\"\" width=\"1023\" height=\"827\" \/> Figure 3.67: create a static route[\/caption]\r\n\r\n&nbsp;\r\n\r\n3. Create a Policy that allows the traffic from Trust Zone to VPN Zone and vice versa.\r\n\r\n[caption id=\"attachment_1270\" align=\"aligncenter\" width=\"1031\"]<img class=\"wp-image-1270 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042.png\" alt=\"\" width=\"1031\" height=\"827\" \/> Figure 3.68: create two policies[\/caption]\r\n\r\n4. Create an IKE profile with following information:\r\n<div class=\"textbox\">\r\n\r\nName: IKEProfile\r\n\r\nDH Group: Group5\r\n\r\nAuthentication: md5\r\n\r\nEncryption: aes-128-cbc\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_1271\" align=\"aligncenter\" width=\"1027\"]<img class=\"wp-image-1271 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104.png\" alt=\"\" width=\"1027\" height=\"828\" \/> Figure 3.69: create a IKE Crypto Profile[\/caption]\r\n\r\n&nbsp;\r\n\r\n5. Create an IPSEC profile with following information:\r\n<div class=\"textbox\">\r\n\r\nName: IPSECProfile\r\n\r\nDH Group: Group2\r\n\r\nAuthentication: sha1\r\n\r\nEncryption: aes-128-cbc\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_1272\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-1272 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123201.png\" alt=\"\" width=\"1024\" height=\"827\" \/> Figure 3.70: create a IPSEC Crypto Profile[\/caption]\r\n\r\n&nbsp;\r\n\r\n6. Create an IKE Gateway with following information:\r\n<div class=\"textbox\">\r\n\r\nName: IKE_Gateway\r\n\r\ninterface: ethernet 1\/1\r\n\r\nLocal IP Address: 10.10.10.2\/24\r\n\r\nPeer Address: 10.10.10.1\r\n\r\nPre-SharedKey: cisco123\r\n\r\nAdvanced Options&gt; Exchange mode: main\r\n\r\nAdvanced Options&gt; IKE Crypto Profile: IKEProfile\r\n\r\n<\/div>\r\n&nbsp;\r\n\r\n[caption id=\"attachment_1273\" align=\"aligncenter\" width=\"628\"]<img class=\"wp-image-1273 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123310.png\" alt=\"\" width=\"628\" height=\"505\" \/> Figure 3.71: create a IKE Gateway[\/caption]\r\n\r\n7. Create an IPSEC tunnel with following information:\r\n<div class=\"textbox\">\r\n\r\nName: IPSEC\r\n\r\nTunnel Interface: tunnel1\r\n\r\nIKE Gateway: IKE_Gateway\r\n\r\nIPSEC Crypto Profile: IPSECProfile\r\n\r\nProxy ID: \u00a0 ProxyID: LocalRemote\u00a0 \u00a0 \u00a0 Local: 192.168.10.0\/24\u00a0 \u00a0 Remote: 192.168.20.0\/24\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_1274\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-1274 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503.png\" alt=\"\" width=\"1026\" height=\"828\" \/> Figure 3.72: create a Proxy ID[\/caption]\r\n\r\n&nbsp;\r\n\r\n8. Successful ping from 192.168.10.2 to 192.168.20.2\r\n\r\n[caption id=\"attachment_1275\" align=\"aligncenter\" width=\"679\"]<img class=\"wp-image-1275 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124238.png\" alt=\"\" width=\"679\" height=\"176\" \/> Figure 3.73: Verify successful ping[\/caption]\r\n\r\n9. Check status of your tunnel.\r\n\r\n[caption id=\"attachment_1276\" align=\"aligncenter\" width=\"1023\"]<img class=\"wp-image-1276 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124330.png\" alt=\"\" width=\"1023\" height=\"825\" \/> Figure 3.74: Verify tunnel status[\/caption]\r\n<h2>FortiGate<\/h2>\r\n<ol>\r\n \t<li>Now, add the FortiGate device in the following diagram.<\/li>\r\n<\/ol>\r\n[caption id=\"attachment_1237\" align=\"aligncenter\" width=\"796\"]<img class=\"wp-image-1237 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131926.png\" alt=\"\" width=\"796\" height=\"324\" \/> Figure 3.75: Main Senario and adding FortiGate[\/caption]\r\n\r\n&nbsp;\r\n\r\n2. Configure a custom VPN Tunnel with following information:\r\n<div class=\"textbox\">\r\n<ul>\r\n \t<li>Remote Gateway<\/li>\r\n<\/ul>\r\n<p style=\"padding-left: 80px\">IP Address: 10.10.10.2<\/p>\r\n<p style=\"padding-left: 80px\">Interface: Port 3<\/p>\r\n\r\n<ul>\r\n \t<li>Authentication<\/li>\r\n<\/ul>\r\n<p style=\"padding-left: 80px\">Method: Pre-shared Key<\/p>\r\n<p style=\"padding-left: 80px\">Pre-shared Key: cisco123<\/p>\r\n\r\n<ul>\r\n \t<li>Phase 1 Proposal<\/li>\r\n<\/ul>\r\n<p style=\"padding-left: 80px\">Encryption: AES128 \u00a0 \u00a0 \u00a0 Authentication: MD5\u00a0 \u00a0 Group: 5<\/p>\r\n\r\n<ul>\r\n \t<li>Phase 2 Selectors<\/li>\r\n<\/ul>\r\n<p style=\"padding-left: 80px\">Local Address: 192.168.20.0\/24\u00a0 \u00a0 Remote Address: 192.168.10.0\/24<\/p>\r\n<p style=\"padding-left: 80px\">Advanced: Encryption: AES128 \u00a0 Authentication: SHA1\u00a0 Group: 2<\/p>\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_1286\" align=\"aligncenter\" width=\"1024\"]<img class=\"wp-image-1286 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134307.png\" alt=\"\" width=\"1024\" height=\"817\" \/> Figure 3.76: Remote IP address configuration[\/caption]\r\n\r\n[caption id=\"attachment_1287\" align=\"aligncenter\" width=\"1028\"]<img class=\"wp-image-1287 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323.png\" alt=\"\" width=\"1028\" height=\"819\" \/> Figure 3.77: Pre-shared Key[\/caption]\r\n\r\n[caption id=\"attachment_1293\" align=\"aligncenter\" width=\"1021\"]<img class=\"wp-image-1293 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135219-1.png\" alt=\"\" width=\"1021\" height=\"821\" \/> Figure 3.78: Phase 1 Proposal[\/caption]\r\n\r\n[caption id=\"attachment_1289\" align=\"aligncenter\" width=\"1023\"]<img class=\"wp-image-1289 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134350.png\" alt=\"\" width=\"1023\" height=\"827\" \/> Figure 3.79: Local and Remote subnets[\/caption]\r\n\r\n[caption id=\"attachment_1292\" align=\"aligncenter\" width=\"1027\"]<img class=\"wp-image-1292 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306.png\" alt=\"\" width=\"1027\" height=\"828\" \/> Figure 3.80: Phase 2 Proposal[\/caption]\r\n\r\n3. Create a Security IPV4 Policy from Tunnel to Port2 and from Port2 to Tunnel and allow all traffic (NAT should be disabled)\r\n\r\n[caption id=\"attachment_1280\" align=\"aligncenter\" width=\"1019\"]<img class=\"wp-image-1280 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130300.png\" alt=\"\" width=\"1019\" height=\"826\" \/> Figure 3.81: Create two policies from tunnel to port2 and from port2 to tunnel[\/caption]\r\n\r\n[caption id=\"attachment_1281\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-1281 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329.png\" alt=\"\" width=\"1026\" height=\"828\" \/> Figure 3.82: Create two policies from tunnel to port2 and from port2 to tunnel[\/caption]\r\n\r\n&nbsp;\r\n\r\n4. Create a static route with following information:\r\n<div class=\"textbox\">\r\n\r\nDestination: 192.168.10.0\/24\r\n\r\nInterface: Tunnel\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_1282\" align=\"aligncenter\" width=\"1027\"]<img class=\"wp-image-1282 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533.png\" alt=\"\" width=\"1027\" height=\"830\" \/> Figure 3.83 Create a static route[\/caption]\r\n\r\n&nbsp;\r\n\r\n5. Verify your configuration ( FortiGate and Palo Alto)\r\n\r\n[caption id=\"attachment_1284\" align=\"aligncenter\" width=\"1029\"]<img class=\"wp-image-1284 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550.png\" alt=\"\" width=\"1029\" height=\"826\" \/> Figure 3.84 Verify tunnel status[\/caption]\r\n\r\n6. You should be able to ping from WebTerm2 to WebTerm3.\r\n\r\n[caption id=\"attachment_1283\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-1283 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629.png\" alt=\"\" width=\"1026\" height=\"834\" \/> Figure 3.85 Verify successful ping[\/caption]\r\n\r\n&nbsp;\r\n\r\n<strong>Document is generated by Michael Sue<\/strong>","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Create a tunnel in Cisco router<\/li>\n<li>Create a tunnel in Palo Alto<\/li>\n<li>Connect a tunnel from Cisco router to Palo Alto<\/li>\n<li>Connect a FortiGate tunnel to Palo Alto<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox shaded\">\n<p><strong>Scenario<\/strong>:\u00a0 We are going to do a site-to-site VPN from Cisco to Palo Alto and then expand it between FortiGate and Palo Alto.<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_1232\" aria-describedby=\"caption-attachment-1232\" style=\"width: 790px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1232 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131201.png\" alt=\"\" width=\"790\" height=\"312\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131201.png 790w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131201-300x118.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131201-768x303.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131201-65x26.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131201-225x89.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131201-350x138.png 350w\" sizes=\"auto, (max-width: 790px) 100vw, 790px\" \/><figcaption id=\"caption-attachment-1232\" class=\"wp-caption-text\">Figure 3.65: Main Scenario<\/figcaption><\/figure>\n<div style=\"text-align: left;\">\n<table style=\"width: 100%\">\n<caption>Table 3.16: Addressing Table<\/caption>\n<tbody>\n<tr>\n<td style=\"width: 38.1989%\"><strong>Device<\/strong><\/td>\n<td style=\"width: 61.7516%\"><strong>Configuration<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 38.1989%\">Palo Alto<\/td>\n<td style=\"width: 61.7516%\">Ethernet 1\/1: 10.10.10.2\/24 \u2013 Type: Layer3<\/p>\n<p>Ethernet 1\/2: 192.168.10.1\/24 \u2013 Type: Layer3<\/p>\n<p>Management: 192.168.0.1\/24\u2013 Type: Layer3<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 38.1989%\">Router (7200)<\/td>\n<td style=\"width: 61.7516%\">G1\/0: 10.10.10.1\/24<\/p>\n<p>G2\/0: 192.168.20.1\/24<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 38.1989%\">WebTerm-1<\/td>\n<td style=\"width: 61.7516%\">192.168.0.2\/24<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 38.1989%\">WebTerm-2<\/td>\n<td style=\"width: 61.7516%\">IPV4: 192.168.10.2\/24 \u00a0 GW: 192.168.10.1<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 38.1989%\">WebTerm-3<\/td>\n<td style=\"width: 61.7516%\">IPV4: 192.168.20.2\/24 \u00a0 GW: 192.168.20.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2>Zones<\/h2>\n<div style=\"text-align: left;\">\n<table style=\"width: 100%;height: 54px\">\n<caption>Table 3.17: Zones<\/caption>\n<tbody>\n<tr style=\"height: 18px\">\n<td style=\"width: 409.625px;height: 18px\"><strong>Zones<\/strong><\/td>\n<td style=\"width: 567.688px;height: 18px\"><strong>Interface<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 18px\">\n<td style=\"width: 409.625px;height: 18px\">VPN<\/td>\n<td style=\"width: 567.688px;height: 18px\">Ethernet 1 \/1<\/td>\n<\/tr>\n<tr style=\"height: 18px\">\n<td style=\"width: 409.625px;height: 18px\">Trust<\/td>\n<td style=\"width: 567.688px;height: 18px\">Ethernet 1 \/2<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>&nbsp;<\/p>\n<h2><strong>Cisco<\/strong><\/h2>\n<ol>\n<li style=\"font-weight: 400\">First, configure the router with the following commands:<\/li>\n<\/ol>\n<div class=\"textbox\">\n<pre>ip access-list extended Crypto_Acl\r\npermit ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255\r\n\r\n\r\ncrypto isakmp policy 1\r\nencr aes\r\nhash md5\r\nauthentication pre-share\r\ngroup 5\r\n\r\n\r\ncrypto isakmp key cisco123 address 10.10.10.2\r\ncrypto ipsec transform-set TSET esp-aes esp-sha-hmac\r\n\r\n\r\n\r\ncrypto map CMAP 10 ipsec-isakmp\r\nset peer 10.10.10.2\r\nset transform-set TSET\r\nmatch address Crypto_Acl\r\n\r\n\r\ninterface Gi1\/0\r\ncrypto map CMAP\r\n\r\nip route 0.0.0.0 0.0.0.0 10.10.10.2<\/pre>\n<p>&nbsp;<\/p>\n<\/div>\n<h2>Palo Alto<\/h2>\n<ol>\n<li style=\"font-weight: 400\">Create a tunnel and assign the tunnel to VPN Zone<\/li>\n<\/ol>\n<figure id=\"attachment_1266\" aria-describedby=\"caption-attachment-1266\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1266 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905.png\" alt=\"Figure 3.66: create a tunnel\" width=\"1026\" height=\"824\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905-300x241.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905-1024x822.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905-768x617.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905-225x181.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131905-350x281.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-1266\" class=\"wp-caption-text\">Figure 3.66: create a tunnel<\/figcaption><\/figure>\n<p>2. Create a static route with following information:<\/p>\n<div class=\"textbox\">\n<p>Destination Address: 192.168.20.0\/24<\/p>\n<p>Interface: tunnel1<\/p>\n<p>Next Hope: none<\/p>\n<\/div>\n<figure id=\"attachment_1269\" aria-describedby=\"caption-attachment-1269\" style=\"width: 1023px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1269 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131936.png\" alt=\"\" width=\"1023\" height=\"827\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131936.png 1023w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131936-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131936-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131936-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131936-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-131936-350x283.png 350w\" sizes=\"auto, (max-width: 1023px) 100vw, 1023px\" \/><figcaption id=\"caption-attachment-1269\" class=\"wp-caption-text\">Figure 3.67: create a static route<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>3. Create a Policy that allows the traffic from Trust Zone to VPN Zone and vice versa.<\/p>\n<figure id=\"attachment_1270\" aria-describedby=\"caption-attachment-1270\" style=\"width: 1031px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1270 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042.png\" alt=\"\" width=\"1031\" height=\"827\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042.png 1031w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042-300x241.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042-1024x821.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042-768x616.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042-225x180.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-132042-350x281.png 350w\" sizes=\"auto, (max-width: 1031px) 100vw, 1031px\" \/><figcaption id=\"caption-attachment-1270\" class=\"wp-caption-text\">Figure 3.68: create two policies<\/figcaption><\/figure>\n<p>4. Create an IKE profile with following information:<\/p>\n<div class=\"textbox\">\n<p>Name: IKEProfile<\/p>\n<p>DH Group: Group5<\/p>\n<p>Authentication: md5<\/p>\n<p>Encryption: aes-128-cbc<\/p>\n<\/div>\n<figure id=\"attachment_1271\" aria-describedby=\"caption-attachment-1271\" style=\"width: 1027px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1271 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104.png\" alt=\"\" width=\"1027\" height=\"828\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104.png 1027w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104-300x242.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104-1024x826.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104-768x619.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104-225x181.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123104-350x282.png 350w\" sizes=\"auto, (max-width: 1027px) 100vw, 1027px\" \/><figcaption id=\"caption-attachment-1271\" class=\"wp-caption-text\">Figure 3.69: create a IKE Crypto Profile<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>5. Create an IPSEC profile with following information:<\/p>\n<div class=\"textbox\">\n<p>Name: IPSECProfile<\/p>\n<p>DH Group: Group2<\/p>\n<p>Authentication: sha1<\/p>\n<p>Encryption: aes-128-cbc<\/p>\n<\/div>\n<figure id=\"attachment_1272\" aria-describedby=\"caption-attachment-1272\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1272 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123201.png\" alt=\"\" width=\"1024\" height=\"827\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123201.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123201-300x242.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123201-768x620.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123201-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123201-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123201-350x283.png 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-1272\" class=\"wp-caption-text\">Figure 3.70: create a IPSEC Crypto Profile<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>6. Create an IKE Gateway with following information:<\/p>\n<div class=\"textbox\">\n<p>Name: IKE_Gateway<\/p>\n<p>interface: ethernet 1\/1<\/p>\n<p>Local IP Address: 10.10.10.2\/24<\/p>\n<p>Peer Address: 10.10.10.1<\/p>\n<p>Pre-SharedKey: cisco123<\/p>\n<p>Advanced Options&gt; Exchange mode: main<\/p>\n<p>Advanced Options&gt; IKE Crypto Profile: IKEProfile<\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_1273\" aria-describedby=\"caption-attachment-1273\" style=\"width: 628px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1273 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123310.png\" alt=\"\" width=\"628\" height=\"505\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123310.png 628w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123310-300x241.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123310-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123310-225x181.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123310-350x281.png 350w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><figcaption id=\"caption-attachment-1273\" class=\"wp-caption-text\">Figure 3.71: create a IKE Gateway<\/figcaption><\/figure>\n<p>7. Create an IPSEC tunnel with following information:<\/p>\n<div class=\"textbox\">\n<p>Name: IPSEC<\/p>\n<p>Tunnel Interface: tunnel1<\/p>\n<p>IKE Gateway: IKE_Gateway<\/p>\n<p>IPSEC Crypto Profile: IPSECProfile<\/p>\n<p>Proxy ID: \u00a0 ProxyID: LocalRemote\u00a0 \u00a0 \u00a0 Local: 192.168.10.0\/24\u00a0 \u00a0 Remote: 192.168.20.0\/24<\/p>\n<\/div>\n<figure id=\"attachment_1274\" aria-describedby=\"caption-attachment-1274\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1274 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503.png\" alt=\"\" width=\"1026\" height=\"828\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503-300x242.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503-1024x826.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503-768x620.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-123503-350x282.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-1274\" class=\"wp-caption-text\">Figure 3.72: create a Proxy ID<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>8. Successful ping from 192.168.10.2 to 192.168.20.2<\/p>\n<figure id=\"attachment_1275\" aria-describedby=\"caption-attachment-1275\" style=\"width: 679px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1275 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124238.png\" alt=\"\" width=\"679\" height=\"176\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124238.png 679w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124238-300x78.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124238-65x17.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124238-225x58.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124238-350x91.png 350w\" sizes=\"auto, (max-width: 679px) 100vw, 679px\" \/><figcaption id=\"caption-attachment-1275\" class=\"wp-caption-text\">Figure 3.73: Verify successful ping<\/figcaption><\/figure>\n<p>9. Check status of your tunnel.<\/p>\n<figure id=\"attachment_1276\" aria-describedby=\"caption-attachment-1276\" style=\"width: 1023px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1276 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124330.png\" alt=\"\" width=\"1023\" height=\"825\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124330.png 1023w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124330-300x242.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124330-768x619.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124330-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124330-225x181.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-124330-350x282.png 350w\" sizes=\"auto, (max-width: 1023px) 100vw, 1023px\" \/><figcaption id=\"caption-attachment-1276\" class=\"wp-caption-text\">Figure 3.74: Verify tunnel status<\/figcaption><\/figure>\n<h2>FortiGate<\/h2>\n<ol>\n<li>Now, add the FortiGate device in the following diagram.<\/li>\n<\/ol>\n<figure id=\"attachment_1237\" aria-describedby=\"caption-attachment-1237\" style=\"width: 796px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1237 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131926.png\" alt=\"\" width=\"796\" height=\"324\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131926.png 796w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131926-300x122.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131926-768x313.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131926-65x26.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131926-225x92.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-23-131926-350x142.png 350w\" sizes=\"auto, (max-width: 796px) 100vw, 796px\" \/><figcaption id=\"caption-attachment-1237\" class=\"wp-caption-text\">Figure 3.75: Main Senario and adding FortiGate<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>2. Configure a custom VPN Tunnel with following information:<\/p>\n<div class=\"textbox\">\n<ul>\n<li>Remote Gateway<\/li>\n<\/ul>\n<p style=\"padding-left: 80px\">IP Address: 10.10.10.2<\/p>\n<p style=\"padding-left: 80px\">Interface: Port 3<\/p>\n<ul>\n<li>Authentication<\/li>\n<\/ul>\n<p style=\"padding-left: 80px\">Method: Pre-shared Key<\/p>\n<p style=\"padding-left: 80px\">Pre-shared Key: cisco123<\/p>\n<ul>\n<li>Phase 1 Proposal<\/li>\n<\/ul>\n<p style=\"padding-left: 80px\">Encryption: AES128 \u00a0 \u00a0 \u00a0 Authentication: MD5\u00a0 \u00a0 Group: 5<\/p>\n<ul>\n<li>Phase 2 Selectors<\/li>\n<\/ul>\n<p style=\"padding-left: 80px\">Local Address: 192.168.20.0\/24\u00a0 \u00a0 Remote Address: 192.168.10.0\/24<\/p>\n<p style=\"padding-left: 80px\">Advanced: Encryption: AES128 \u00a0 Authentication: SHA1\u00a0 Group: 2<\/p>\n<\/div>\n<figure id=\"attachment_1286\" aria-describedby=\"caption-attachment-1286\" style=\"width: 1024px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1286 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134307.png\" alt=\"\" width=\"1024\" height=\"817\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134307.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134307-300x239.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134307-768x613.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134307-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134307-225x180.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134307-350x279.png 350w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption id=\"caption-attachment-1286\" class=\"wp-caption-text\">Figure 3.76: Remote IP address configuration<\/figcaption><\/figure>\n<figure id=\"attachment_1287\" aria-describedby=\"caption-attachment-1287\" style=\"width: 1028px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1287 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323.png\" alt=\"\" width=\"1028\" height=\"819\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323.png 1028w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323-300x239.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323-1024x816.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323-768x612.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323-225x179.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134323-350x279.png 350w\" sizes=\"auto, (max-width: 1028px) 100vw, 1028px\" \/><figcaption id=\"caption-attachment-1287\" class=\"wp-caption-text\">Figure 3.77: Pre-shared Key<\/figcaption><\/figure>\n<figure id=\"attachment_1293\" aria-describedby=\"caption-attachment-1293\" style=\"width: 1021px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1293 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135219-1.png\" alt=\"\" width=\"1021\" height=\"821\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135219-1.png 1021w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135219-1-300x241.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135219-1-768x618.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135219-1-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135219-1-225x181.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135219-1-350x281.png 350w\" sizes=\"auto, (max-width: 1021px) 100vw, 1021px\" \/><figcaption id=\"caption-attachment-1293\" class=\"wp-caption-text\">Figure 3.78: Phase 1 Proposal<\/figcaption><\/figure>\n<figure id=\"attachment_1289\" aria-describedby=\"caption-attachment-1289\" style=\"width: 1023px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1289 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134350.png\" alt=\"\" width=\"1023\" height=\"827\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134350.png 1023w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134350-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134350-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134350-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134350-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-134350-350x283.png 350w\" sizes=\"auto, (max-width: 1023px) 100vw, 1023px\" \/><figcaption id=\"caption-attachment-1289\" class=\"wp-caption-text\">Figure 3.79: Local and Remote subnets<\/figcaption><\/figure>\n<figure id=\"attachment_1292\" aria-describedby=\"caption-attachment-1292\" style=\"width: 1027px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1292 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306.png\" alt=\"\" width=\"1027\" height=\"828\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306.png 1027w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306-300x242.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306-1024x826.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306-768x619.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306-225x181.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-135306-350x282.png 350w\" sizes=\"auto, (max-width: 1027px) 100vw, 1027px\" \/><figcaption id=\"caption-attachment-1292\" class=\"wp-caption-text\">Figure 3.80: Phase 2 Proposal<\/figcaption><\/figure>\n<p>3. Create a Security IPV4 Policy from Tunnel to Port2 and from Port2 to Tunnel and allow all traffic (NAT should be disabled)<\/p>\n<figure id=\"attachment_1280\" aria-describedby=\"caption-attachment-1280\" style=\"width: 1019px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1280 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130300.png\" alt=\"\" width=\"1019\" height=\"826\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130300.png 1019w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130300-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130300-768x623.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130300-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130300-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130300-350x284.png 350w\" sizes=\"auto, (max-width: 1019px) 100vw, 1019px\" \/><figcaption id=\"caption-attachment-1280\" class=\"wp-caption-text\">Figure 3.81: Create two policies from tunnel to port2 and from port2 to tunnel<\/figcaption><\/figure>\n<figure id=\"attachment_1281\" aria-describedby=\"caption-attachment-1281\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1281 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329.png\" alt=\"\" width=\"1026\" height=\"828\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329-300x242.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329-1024x826.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329-768x620.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130329-350x282.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-1281\" class=\"wp-caption-text\">Figure 3.82: Create two policies from tunnel to port2 and from port2 to tunnel<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>4. Create a static route with following information:<\/p>\n<div class=\"textbox\">\n<p>Destination: 192.168.10.0\/24<\/p>\n<p>Interface: Tunnel<\/p>\n<\/div>\n<figure id=\"attachment_1282\" aria-describedby=\"caption-attachment-1282\" style=\"width: 1027px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1282 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533.png\" alt=\"\" width=\"1027\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533.png 1027w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533-300x242.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130533-350x283.png 350w\" sizes=\"auto, (max-width: 1027px) 100vw, 1027px\" \/><figcaption id=\"caption-attachment-1282\" class=\"wp-caption-text\">Figure 3.83 Create a static route<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p>5. Verify your configuration ( FortiGate and Palo Alto)<\/p>\n<figure id=\"attachment_1284\" aria-describedby=\"caption-attachment-1284\" style=\"width: 1029px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1284 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550.png\" alt=\"\" width=\"1029\" height=\"826\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550.png 1029w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550-300x241.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550-1024x822.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550-768x616.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550-65x52.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550-225x181.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130550-350x281.png 350w\" sizes=\"auto, (max-width: 1029px) 100vw, 1029px\" \/><figcaption id=\"caption-attachment-1284\" class=\"wp-caption-text\">Figure 3.84 Verify tunnel status<\/figcaption><\/figure>\n<p>6. You should be able to ping from WebTerm2 to WebTerm3.<\/p>\n<figure id=\"attachment_1283\" aria-describedby=\"caption-attachment-1283\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1283 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629.png\" alt=\"\" width=\"1026\" height=\"834\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629-300x244.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629-1024x832.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629-768x624.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629-225x183.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2026\/01\/Screenshot-2026-01-26-130629-350x285.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-1283\" class=\"wp-caption-text\">Figure 3.85 Verify successful ping<\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p><strong>Document is generated by Michael Sue<\/strong><\/p>\n","protected":false},"author":1562,"menu_order":4,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-1228","chapter","type-chapter","status-publish","hentry"],"part":123,"_links":{"self":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/1228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/users\/1562"}],"version-history":[{"count":25,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/1228\/revisions"}],"predecessor-version":[{"id":1348,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/1228\/revisions\/1348"}],"part":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/123"}],"metadata":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/1228\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=1228"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=1228"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=1228"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/license?post=1228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}