Configuration Guide Fortigate: Thegreenbow Ipsec VPN Client
Configuration Guide Fortigate: Thegreenbow Ipsec VPN Client
Configuration Guide Fortigate: Thegreenbow Ipsec VPN Client
Configuration Guide
FortiGate
Website: www.thegreenbow.com
Contact: support@thegreenbow.com
Table of Contents
1 Introduction ............................................................................................................................................ 3
1.1 Goal of this document.................................................................................................................... 3
1.2 VPN Network topology .................................................................................................................. 3
1.3 FortiGate Restrictions .................................................................................................................... 3
1.4 FortiGate VPN Gateway ................................................................................................................. 3
1.5 FortiGate VPN Gateway product info ............................................................................................ 3
2 FortiGate VPN configuration .................................................................................................................. 4
3 TheGreenBow IPsec VPN Client configuration ..................................................................................... 11
3.1 VPN Client - IKE Auth Configuration ............................................................................................ 11
3.2 VPN Client Phase 2 (Child SA) Configuration ............................................................................... 12
3.3 Open IPsec VPN tunnels ............................................................................................................... 13
4 Tools in case of trouble......................................................................................................................... 14
4.1 A good network analyser: Wireshark........................................................................................... 14
5 VPN IPsec Troubleshooting................................................................................................................... 15
5.1 “NO_PROPOSAL_CHOSEN” error (wrong IKE Auth)..................................................................... 15
5.2 “AUTHENTICATION_FAILED” error .............................................................................................. 15
5.3 “No user certificate available for the connexion” error .............................................................. 15
5.4 “Remote IDr rejected” error ........................................................................................................ 15
5.5 “NO_PROPOSAL_CHOSEN” error (wrong CHILD SA).................................................................... 15
5.6 “FAILED_CP_REQUIRED” error ..................................................................................................... 16
5.7 I clicked on “Open tunnel”, but nothing happens. ...................................................................... 16
5.8 The VPN tunnel is up but I can’t ping ! ........................................................................................ 16
6 Contacts ................................................................................................................................................ 17
2
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
1 Introduction
1.1 Goal of this document
This configuration guide describes how to configure TheGreenBow IPsec VPN Client software with a FortiGate
VPN router to establish VPN connections for remote access to corporate network.
mygateway.dyndns.org
192.168.210.1
192.168.210.78
Internet
IPsec VPN Client FortiGate
(Remote)
192.168.10.21
192.168.210.3
3
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
4
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
Note :
For IKEv1, simply select Version 1. VPN Client side, configuration needs to be created under IKEv1.
5
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
6
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
7
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
8
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
9
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
10
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
This configuration is one example of what can be accomplished in term of User Authentication. You may want
to refer to either the FortiGate router user guide or TheGreenBow IPsec VPN Client software User Guide for
more details on User Authentication options.
11
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
Child SA Configuration
12
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
13
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
Wireshark is a free software that can be used for packet and traffic analysis. It shows IP or TCP packets
received on a network card. This tool is available on website www.wireshark.org. It can be used to follow
protocol exchange between two devices. For installation and use details, read its specific documentation
(www.wireshark.org/docs/).
14
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
If you have an “NO_PROPOSAL_CHOSEN” error you might have a wrong Phase 1 [IKE Auth], check if the
encryption algorithms are the same on each side of the VPN tunnel.
If you have an “AUTHENTICATION_FAILED” error, it means that the certificate or the preshared key is not
matching. Check the Gateway if the user certificate or preshared key is valid.
Check if the certificate is selected or the Token (smartcard) is available on the computer.
The “Remote ID” value (see “Protocol” tab) does not match what the remote endpoint is expected.
15
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
If you have an “NO_PROPOSAL_CHOSEN” error, check that the “Child SA” encryption algorithms are the same
on each side of the VPN Tunnel.
If you have an “FAILED_CP_REQUIRED” error, then the Gateway is configured to use Mode CP. Go to Traffic
selectors and enable "Request configuration from the gateway".
Read logs of each VPN tunnel endpoint. IKE requests can be dropped by firewalls. An IPsec Client uses UDP
port 500.
Check if the remote server is online.
16
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Configuration Guide
6 Contacts
News and updates on TheGreenBow web site: www.thegreenbow.com
17
IPsec VPN Router Configuration Property of TheGreenBow – Sistech S.A. © 2018
Secure, Strong, Simple
TheGreenBow Security Software