<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Fortinet &#8211; RAGASYS SISTEMAS</title>
	<atom:link href="https://blog.ragasys.es/category/fortinet/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.ragasys.es</link>
	<description>Soporte técnico para las TIC</description>
	<lastBuildDate>Thu, 05 Mar 2026 12:32:50 +0000</lastBuildDate>
	<language>es</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/05/logoRGS_18_05_2020.png?fit=32%2C32&#038;ssl=1</url>
	<title>Fortinet &#8211; RAGASYS SISTEMAS</title>
	<link>https://blog.ragasys.es</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">111701399</site>	<item>
		<title>Configuración Fortigate – VPN IPSEC de Acceso Remoto</title>
		<link>https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto</link>
					<comments>https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Thu, 05 Mar 2026 08:42:26 +0000</pubDate>
				<category><![CDATA[Accesos remotos]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Forticlient]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[IPsec]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Routing]]></category>
		<category><![CDATA[TIC]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=21841</guid>

					<description><![CDATA[Hola a tod@s. En este post vamos a ver como configurar una VPN IPSEC de acceso remoto en un firewall Fortigate, con este tipo de VPN usando el protocolo IPSec nos podemos conectar desde cualquier equipo con conexión a Internet&#8230; <a href="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s.</p>
<p>En este post vamos a ver como configurar una VPN IPSEC de acceso remoto en un firewall Fortigate, con este tipo de VPN usando el protocolo IPSec nos podemos conectar desde cualquier equipo con conexión a Internet hacia nuestra red interna, dónde todo el tráfico irá encriptado.</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png?ssl=1" data-lbwps-width="1109" data-lbwps-height="618" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21842" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png?fit=1109%2C618&amp;ssl=1" data-orig-size="1109,618" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png?fit=640%2C357&amp;ssl=1" class="aligncenter size-full wp-image-21842" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png?resize=640%2C357&#038;ssl=1" alt="" width="640" height="357" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png?w=1109&amp;ssl=1 1109w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png?resize=595%2C332&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png?resize=960%2C535&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra1.png?resize=768%2C428&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo primero que vamos a realizar será, crear los usuarios locales que accederán a través de la VPN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?ssl=1" data-lbwps-width="1650" data-lbwps-height="392" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2-1536x365.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21843" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?fit=1650%2C392&amp;ssl=1" data-orig-size="1650,392" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?fit=640%2C152&amp;ssl=1" class="aligncenter size-full wp-image-21843" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?resize=640%2C152&#038;ssl=1" alt="" width="640" height="152" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?w=1650&amp;ssl=1 1650w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?resize=595%2C141&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?resize=960%2C228&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?resize=768%2C182&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?resize=1536%2C365&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra2.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para una correcta administración, los usuarios que nos hemos creado anteriormente los vamos a anidar en un grupo:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?ssl=1" data-lbwps-width="1692" data-lbwps-height="444" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3-1536x403.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21844" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?fit=1692%2C444&amp;ssl=1" data-orig-size="1692,444" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?fit=640%2C168&amp;ssl=1" class="aligncenter size-full wp-image-21844" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?resize=640%2C168&#038;ssl=1" alt="" width="640" height="168" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?w=1692&amp;ssl=1 1692w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?resize=595%2C156&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?resize=960%2C252&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?resize=768%2C202&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?resize=1536%2C403&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Una vez creados los usuarios y grupos, vamos a crearnos el túnel IPSec, para ello, accedemos a <strong>VPN &gt; Túneles Ipsec &gt; Crear nuevo &gt; IPsec Tunnel</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?ssl=1" data-lbwps-width="1617" data-lbwps-height="376" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4-1536x357.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21845" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?fit=1617%2C376&amp;ssl=1" data-orig-size="1617,376" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?fit=640%2C149&amp;ssl=1" class="aligncenter size-full wp-image-21845" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?resize=640%2C149&#038;ssl=1" alt="" width="640" height="149" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?w=1617&amp;ssl=1 1617w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?resize=595%2C138&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?resize=960%2C223&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?resize=768%2C179&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?resize=1536%2C357&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra4.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Configuración de VPN</strong>, le indicamos un <strong>nombre</strong> y seleccionamos <strong>Acceso remoto, Siguiente</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?ssl=1" data-lbwps-width="1669" data-lbwps-height="398" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5-1536x366.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21846" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?fit=1669%2C398&amp;ssl=1" data-orig-size="1669,398" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?fit=640%2C153&amp;ssl=1" class="aligncenter size-full wp-image-21846" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?resize=640%2C153&#038;ssl=1" alt="" width="640" height="153" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?w=1669&amp;ssl=1 1669w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?resize=595%2C142&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?resize=960%2C229&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?resize=768%2C183&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?resize=1536%2C366&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra5.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Autenticación</strong>, le indicamos la interface de entrada, el método de autenticación por llave compartida y el grupo de usuario, este grupo lo eliminaremos de la configuración de las fases más tarde, ya que las políticas de acceso irán configuradas con grupos y no sería necesario, <strong>Siguiente</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?ssl=1" data-lbwps-width="1639" data-lbwps-height="416" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6-1536x390.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21847" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?fit=1639%2C416&amp;ssl=1" data-orig-size="1639,416" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?fit=640%2C163&amp;ssl=1" class="aligncenter size-full wp-image-21847" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?resize=640%2C162&#038;ssl=1" alt="" width="640" height="162" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?w=1639&amp;ssl=1 1639w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?resize=595%2C151&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?resize=960%2C244&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?resize=768%2C195&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?resize=1536%2C390&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra6.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Política y Enrutamiento</strong>, vamos a configurar esta política, que más tarde vamos a eliminar, ya que iremos aplicando políticas más granulares y restrictivas, habilitamos el Split Tunnel, esto hará que los usuarios que se conecten a la VPN, tengan la salida a Internet por su propia conexión y no por la nuestra, <strong>Siguiente</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?ssl=1" data-lbwps-width="1637" data-lbwps-height="459" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7-1536x431.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21848" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?fit=1637%2C459&amp;ssl=1" data-orig-size="1637,459" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?fit=640%2C179&amp;ssl=1" class="aligncenter size-full wp-image-21848" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?resize=640%2C179&#038;ssl=1" alt="" width="640" height="179" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?w=1637&amp;ssl=1 1637w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?resize=595%2C167&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?resize=960%2C269&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?resize=768%2C215&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?resize=1536%2C431&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra7.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Opciones de cliente</strong>, le indicamos que guarde la contraseña, y habilitamos el Keep Alive, <strong>Crear</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?ssl=1" data-lbwps-width="1645" data-lbwps-height="413" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8-1536x386.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21849" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?fit=1645%2C413&amp;ssl=1" data-orig-size="1645,413" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?fit=640%2C161&amp;ssl=1" class="aligncenter size-full wp-image-21849" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?resize=640%2C161&#038;ssl=1" alt="" width="640" height="161" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?w=1645&amp;ssl=1 1645w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?resize=595%2C149&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?resize=960%2C241&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?resize=768%2C193&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?resize=1536%2C386&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí nos indica todo lo que hemos configurado, damos a <strong>Mostrar la lista de túnel</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png?ssl=1" data-lbwps-width="1287" data-lbwps-height="482" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21850" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png?fit=1287%2C482&amp;ssl=1" data-orig-size="1287,482" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png?fit=640%2C240&amp;ssl=1" class="aligncenter size-full wp-image-21850" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png?resize=640%2C240&#038;ssl=1" alt="" width="640" height="240" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png?w=1287&amp;ssl=1 1287w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png?resize=595%2C223&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png?resize=960%2C360&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra9.png?resize=768%2C288&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Vemos el túnel IPsec que nos ha creado, damos a <strong>Editar</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?ssl=1" data-lbwps-width="1667" data-lbwps-height="401" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10-1536x369.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21851" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?fit=1667%2C401&amp;ssl=1" data-orig-size="1667,401" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?fit=640%2C154&amp;ssl=1" class="aligncenter size-full wp-image-21851" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?resize=640%2C154&#038;ssl=1" alt="" width="640" height="154" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?w=1667&amp;ssl=1 1667w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?resize=595%2C143&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?resize=960%2C231&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?resize=768%2C185&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?resize=1536%2C369&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Convertimos a túnel personalizado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?ssl=1" data-lbwps-width="1459" data-lbwps-height="691" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21852" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?fit=1459%2C691&amp;ssl=1" data-orig-size="1459,691" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?fit=640%2C303&amp;ssl=1" class="aligncenter size-full wp-image-21852" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?resize=640%2C303&#038;ssl=1" alt="" width="640" height="303" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?w=1459&amp;ssl=1 1459w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?resize=595%2C282&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?resize=960%2C455&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?resize=768%2C364&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra11.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para la parte de <strong>Red</strong>, configuramos estos parámetros:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra12.png?ssl=1" data-lbwps-width="644" data-lbwps-height="897" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21853" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra12.png?fit=644%2C897&amp;ssl=1" data-orig-size="644,897" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra12.png?fit=640%2C891&amp;ssl=1" class="aligncenter size-full wp-image-21853" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra12.png?resize=640%2C891&#038;ssl=1" alt="" width="640" height="891" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra12.png?w=644&amp;ssl=1 644w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra12.png?resize=595%2C829&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para la parte de <strong>Autenticación</strong>, configuramos lo siguiente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra13.png?ssl=1" data-lbwps-width="926" data-lbwps-height="638" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21854" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra13.png?fit=926%2C638&amp;ssl=1" data-orig-size="926,638" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra13.png?fit=640%2C441&amp;ssl=1" class="aligncenter size-full wp-image-21854" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra13.png?resize=640%2C441&#038;ssl=1" alt="" width="640" height="441" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra13.png?w=926&amp;ssl=1 926w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra13.png?resize=595%2C410&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra13.png?resize=768%2C529&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para la <strong>propuesta de la fase 1</strong>, configuramos estos parámetros:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png?ssl=1" data-lbwps-width="921" data-lbwps-height="650" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21855" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png?fit=921%2C650&amp;ssl=1" data-orig-size="921,650" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png?fit=640%2C452&amp;ssl=1" class="aligncenter size-full wp-image-21855" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png?resize=640%2C452&#038;ssl=1" alt="" width="640" height="452" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png?w=921&amp;ssl=1 921w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png?resize=595%2C420&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png?resize=768%2C542&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra14.png?resize=250%2C175&amp;ssl=1 250w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para <strong>XAUTH</strong>, aquí es donde quitamos el grupo que configuramos al crear el túnel, y para el Grupo de Usuarios, le indicamos que los herede de las políticas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png?ssl=1" data-lbwps-width="997" data-lbwps-height="815" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21856" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png?fit=997%2C815&amp;ssl=1" data-orig-size="997,815" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png?fit=640%2C523&amp;ssl=1" class="aligncenter size-full wp-image-21856" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png?resize=640%2C523&#038;ssl=1" alt="" width="640" height="523" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png?w=997&amp;ssl=1 997w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png?resize=595%2C486&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png?resize=960%2C785&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra15.png?resize=768%2C628&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para los <strong>Selectores de fase 2</strong>, configuramos estos parámetros, damos a <strong>OK</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png?ssl=1" data-lbwps-width="1242" data-lbwps-height="913" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21857" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png?fit=1242%2C913&amp;ssl=1" data-orig-size="1242,913" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png?fit=640%2C471&amp;ssl=1" class="aligncenter size-full wp-image-21857" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png?resize=640%2C470&#038;ssl=1" alt="" width="640" height="470" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png?w=1242&amp;ssl=1 1242w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png?resize=595%2C437&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png?resize=960%2C706&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra16.png?resize=768%2C565&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí tenemos ya el túnel IPsec configurado de modo personalizado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?ssl=1" data-lbwps-width="1784" data-lbwps-height="401" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17-1536x345.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21858" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?fit=1784%2C401&amp;ssl=1" data-orig-size="1784,401" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?fit=640%2C144&amp;ssl=1" class="aligncenter size-full wp-image-21858" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?resize=640%2C144&#038;ssl=1" alt="" width="640" height="144" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?w=1784&amp;ssl=1 1784w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?resize=595%2C134&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?resize=960%2C216&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?resize=768%2C173&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?resize=1536%2C345&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra17.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Antes de seguir, vamos a explicar, estos dos objetos que se han creado al crear la VPN IPsec.</li>
<li>Uno de ellos es, <strong>ipsecra_range</strong>, este objeto es para asignar las direcciones IPs de los equipos que se conecten a nuestra VPN PIsec de acceso remoto:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra18.png?ssl=1" data-lbwps-width="907" data-lbwps-height="467" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21859" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra18.png?fit=907%2C467&amp;ssl=1" data-orig-size="907,467" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra18.png?fit=640%2C330&amp;ssl=1" class="aligncenter size-full wp-image-21859" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra18.png?resize=640%2C330&#038;ssl=1" alt="" width="640" height="330" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra18.png?w=907&amp;ssl=1 907w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra18.png?resize=595%2C306&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra18.png?resize=768%2C395&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>El otro es, <strong>ipsecra_split</strong>, este objeto es un grupo de direcciones que actúa como una «lista blanca» de destinos, su función principal es decirle al cliente VPN (FortiClient) qué tráfico debe enviar obligatoriamente a través del túnel y cuál debe ignorar para que salga por su conexión local a Internet.</li>
<li>Cuando habilitamos el Split Tunneling (Túnel Dividido), el comportamiento es el siguiente:</li>
<li>Si el destino está en el objeto ipsecra_split, el FortiClient enruta ese tráfico por la VPN.</li>
<li>Si el destino NO está ahí, el FortiClient lo envía por la puerta de enlace predeterminada del usuario (su internet doméstico).</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png?ssl=1" data-lbwps-width="1254" data-lbwps-height="695" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21860" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png?fit=1254%2C695&amp;ssl=1" data-orig-size="1254,695" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png?fit=640%2C355&amp;ssl=1" class="aligncenter size-full wp-image-21860" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png?resize=640%2C355&#038;ssl=1" alt="" width="640" height="355" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png?w=1254&amp;ssl=1 1254w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png?resize=595%2C330&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png?resize=960%2C532&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra19.png?resize=768%2C426&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>También podemos ver, que en la interface de red que le indicamos al túnel VPN IPsec, nos ha creado esta interface virtual:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?ssl=1" data-lbwps-width="1494" data-lbwps-height="792" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21861" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?fit=1494%2C792&amp;ssl=1" data-orig-size="1494,792" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?fit=640%2C339&amp;ssl=1" class="aligncenter size-full wp-image-21861" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?resize=640%2C339&#038;ssl=1" alt="" width="640" height="339" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?w=1494&amp;ssl=1 1494w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?resize=595%2C315&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?resize=960%2C509&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?resize=768%2C407&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra20.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para terminar de configurar la VPN IPsec de acceso remoto, debemos de crear las reglas o políticas para que los equipos que se conecten a través de la VPN, tengan acceso a las redes internas configuradas en nuestro firewall, voy a mostrar sólo una de ellas ya que para las demás sería exactamente igual, editamos la regla que se nos creó al crear el túnel IPsec:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png?ssl=1" data-lbwps-width="1257" data-lbwps-height="1080" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21862" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png?fit=1257%2C1080&amp;ssl=1" data-orig-size="1257,1080" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png?fit=640%2C550&amp;ssl=1" class="aligncenter size-full wp-image-21862" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png?resize=640%2C550&#038;ssl=1" alt="" width="640" height="550" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png?w=1257&amp;ssl=1 1257w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png?resize=595%2C511&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png?resize=960%2C825&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra21.png?resize=768%2C660&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con esto ya tendríamos configurada y operativa nuestra VPN IPsec de acceso remoto, ahora desde cualquier equipo con conexión a internet, le instalaremos el Forticlient y configuraremos los parámetros de la VPN IPsec para conectarnos desde cualquier lugar del mundo a las redes internas de nuestra infraestructura, dónde todo el tráfico irá encriptado mediante IPsec:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra22.png?ssl=1" data-lbwps-width="877" data-lbwps-height="701" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra22.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21863" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra22.png?fit=877%2C701&amp;ssl=1" data-orig-size="877,701" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra22.png?fit=640%2C512&amp;ssl=1" class="aligncenter size-full wp-image-21863" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra22.png?resize=640%2C512&#038;ssl=1" alt="" width="640" height="512" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra22.png?w=877&amp;ssl=1 877w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra22.png?resize=595%2C476&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra22.png?resize=768%2C614&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra23.png?ssl=1" data-lbwps-width="876" data-lbwps-height="681" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra23.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21864" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra23.png?fit=876%2C681&amp;ssl=1" data-orig-size="876,681" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra23.png?fit=640%2C498&amp;ssl=1" class="aligncenter size-full wp-image-21864" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra23.png?resize=640%2C498&#038;ssl=1" alt="" width="640" height="498" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra23.png?w=876&amp;ssl=1 876w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra23.png?resize=595%2C463&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra23.png?resize=768%2C597&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra24.png?ssl=1" data-lbwps-width="880" data-lbwps-height="690" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra24.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21865" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra24.png?fit=880%2C690&amp;ssl=1" data-orig-size="880,690" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra24.png?fit=640%2C502&amp;ssl=1" class="aligncenter size-full wp-image-21865" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra24.png?resize=640%2C502&#038;ssl=1" alt="" width="640" height="502" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra24.png?w=880&amp;ssl=1 880w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra24.png?resize=595%2C467&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra24.png?resize=768%2C602&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver ya estamos conectados y nos está sirviendo una dirección IP del rango que habíamos configurado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra25.png?ssl=1" data-lbwps-width="876" data-lbwps-height="683" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra25.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21866" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra25.png?fit=876%2C683&amp;ssl=1" data-orig-size="876,683" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra25.png?fit=640%2C499&amp;ssl=1" class="aligncenter size-full wp-image-21866" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra25.png?resize=640%2C499&#038;ssl=1" alt="" width="640" height="499" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra25.png?w=876&amp;ssl=1 876w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra25.png?resize=595%2C464&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra25.png?resize=768%2C599&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos el túnel levantado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?ssl=1" data-lbwps-width="1665" data-lbwps-height="371" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26-1536x342.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21867" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra26#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?fit=1665%2C371&amp;ssl=1" data-orig-size="1665,371" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra26" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?fit=640%2C143&amp;ssl=1" class="aligncenter size-full wp-image-21867" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?resize=640%2C143&#038;ssl=1" alt="" width="640" height="143" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?w=1665&amp;ssl=1 1665w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?resize=595%2C133&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?resize=960%2C214&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?resize=768%2C171&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?resize=1536%2C342&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra26.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Desde el Monitor IPsec de nuestro Fortigate podemos ver los usuarios conectados a través de la VPN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?ssl=1" data-lbwps-width="1916" data-lbwps-height="663" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27-1536x532.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21868" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra27#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?fit=1916%2C663&amp;ssl=1" data-orig-size="1916,663" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra27" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?fit=640%2C221&amp;ssl=1" class="aligncenter size-full wp-image-21868" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?resize=640%2C221&#038;ssl=1" alt="" width="640" height="221" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?w=1916&amp;ssl=1 1916w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?resize=595%2C206&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?resize=960%2C332&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?resize=768%2C266&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?resize=1536%2C532&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra27.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Desde la opción <strong>VPN &gt; VPN Location Map</strong> podemos ver desde que parte del mundo se están conectando los usuarios que hemos creado y configurado para nuestra VPN IPsec de acceso remoto:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?ssl=1" data-lbwps-width="1918" data-lbwps-height="875" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28-1536x701.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="21869" data-permalink="https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/conffgtvpnipsecra28#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?fit=1918%2C875&amp;ssl=1" data-orig-size="1918,875" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="conffgtvpnipsecra28" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?fit=640%2C292&amp;ssl=1" class="aligncenter size-full wp-image-21869" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?resize=640%2C292&#038;ssl=1" alt="" width="640" height="292" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?w=1918&amp;ssl=1 1918w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?resize=595%2C271&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?resize=960%2C438&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?resize=768%2C350&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?resize=1536%2C701&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2026/02/conffgtvpnipsecra28.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/configuracion-fortigate-vpn-ipsec-de-acceso-remoto/feed</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">21841</post-id>	</item>
		<item>
		<title>Configuración SD-WAN en Firewall Fortigate</title>
		<link>https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate</link>
					<comments>https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 24 Feb 2025 08:40:15 +0000</pubDate>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[sd-wan]]></category>
		<category><![CDATA[TIC]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=19380</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo configurar SD-WAN (Software-Defined WAN) en firewalls fortigate. SD-WAN es una interface virtual compuesta por 2 o más interfaces con acceso a Internet, el objetivo de SD-WAN es hacer un uso&#8230; <a href="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo configurar SD-WAN (Software-Defined WAN) en firewalls fortigate.</p>
<p>SD-WAN es una interface virtual compuesta por 2 o más interfaces con acceso a Internet, el objetivo de SD-WAN es hacer un uso mucho más efectivo de nuestras conexiones hacia internet aplicando diferentes criterios de balanceo.</p>
<ul>
<li>Antes de empezar vamos a ver las interfaces de red que tenemos configuradas en nuestro firewall, para ello, accedemos a <strong>Network &gt; Interfaces </strong>y vemos que ya tenemos configuradas la interface LAN y dos interfaces WAN para la salida a Internet, estas dos interfaces son las que vamos a configurar para la SD-WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?ssl=1" data-lbwps-width="1582" data-lbwps-height="718" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1-1536x697.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19382" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?fit=1582%2C718&amp;ssl=1" data-orig-size="1582,718" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?fit=640%2C291&amp;ssl=1" class="aligncenter size-full wp-image-19382" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?resize=640%2C290&#038;ssl=1" alt="" width="640" height="290" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?w=1582&amp;ssl=1 1582w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?resize=595%2C270&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?resize=960%2C436&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?resize=768%2C349&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?resize=1536%2C697&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?resize=300%2C135&amp;ssl=1 300w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_1.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para empezar a configurar SD-WAN accedemos a <strong>Network &gt; SD-WAN</strong> y la configuramos manualmente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?ssl=1" data-lbwps-width="1462" data-lbwps-height="626" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19383" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?fit=1462%2C626&amp;ssl=1" data-orig-size="1462,626" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?fit=640%2C274&amp;ssl=1" class="aligncenter size-full wp-image-19383" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?resize=640%2C274&#038;ssl=1" alt="" width="640" height="274" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?w=1462&amp;ssl=1 1462w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?resize=595%2C255&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?resize=960%2C411&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?resize=768%2C329&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_2.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre SD-WAN Zones podemos ver que hay creada ya una interface virtual, podemos utilizar esta interface y añadirle los miembros y empezar a trabajar, pero en nuestro caso nos vamos a crear una nueva zona y le vamos a añadir como miembros nuestras dos interfaces WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?ssl=1" data-lbwps-width="1818" data-lbwps-height="333" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3-1536x281.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19384" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?fit=1818%2C333&amp;ssl=1" data-orig-size="1818,333" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?fit=640%2C117&amp;ssl=1" class="aligncenter size-full wp-image-19384" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?resize=640%2C117&#038;ssl=1" alt="" width="640" height="117" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?w=1818&amp;ssl=1 1818w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?resize=595%2C109&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?resize=960%2C176&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?resize=768%2C141&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?resize=1536%2C281&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png?ssl=1" data-lbwps-width="1177" data-lbwps-height="342" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19385" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png?fit=1177%2C342&amp;ssl=1" data-orig-size="1177,342" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png?fit=640%2C186&amp;ssl=1" class="aligncenter size-full wp-image-19385" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png?resize=640%2C186&#038;ssl=1" alt="" width="640" height="186" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png?w=1177&amp;ssl=1 1177w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png?resize=595%2C173&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png?resize=960%2C279&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_4.png?resize=768%2C223&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Le indicamos un nombre y OK:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?ssl=1" data-lbwps-width="1564" data-lbwps-height="935" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5-1536x918.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19386" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?fit=1564%2C935&amp;ssl=1" data-orig-size="1564,935" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?fit=640%2C383&amp;ssl=1" class="aligncenter size-full wp-image-19386" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?resize=640%2C383&#038;ssl=1" alt="" width="640" height="383" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?w=1564&amp;ssl=1 1564w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?resize=595%2C356&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?resize=960%2C574&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?resize=768%2C459&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?resize=1536%2C918&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_5.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos que ya la tenemos creada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?ssl=1" data-lbwps-width="1793" data-lbwps-height="304" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6-1536x260.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19387" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?fit=1793%2C304&amp;ssl=1" data-orig-size="1793,304" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?fit=640%2C109&amp;ssl=1" class="aligncenter size-full wp-image-19387" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?resize=640%2C109&#038;ssl=1" alt="" width="640" height="109" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?w=1793&amp;ssl=1 1793w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?resize=595%2C101&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?resize=960%2C163&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?resize=768%2C130&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?resize=1536%2C260&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_6.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a añadir y configurar las interfaces miembros de esta nueva zona SD-WAN, para ello, accedemos a <strong>Create new &gt; SD-WAN Member</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png?ssl=1" data-lbwps-width="1055" data-lbwps-height="329" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19388" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png?fit=1055%2C329&amp;ssl=1" data-orig-size="1055,329" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png?fit=640%2C199&amp;ssl=1" class="aligncenter size-full wp-image-19388" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png?resize=640%2C200&#038;ssl=1" alt="" width="640" height="200" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png?w=1055&amp;ssl=1 1055w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png?resize=595%2C186&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png?resize=960%2C299&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_7.png?resize=768%2C239&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Añadimos las dos interfaces WAN que tenemos en nuestro firewall, indicándole la zona, la puerta de enlace, el costo y la habilitamos:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?ssl=1" data-lbwps-width="1560" data-lbwps-height="933" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8-1536x919.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19389" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?fit=1560%2C933&amp;ssl=1" data-orig-size="1560,933" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?fit=640%2C383&amp;ssl=1" class="aligncenter size-full wp-image-19389" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?resize=640%2C383&#038;ssl=1" alt="" width="640" height="383" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?w=1560&amp;ssl=1 1560w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?resize=595%2C356&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?resize=960%2C574&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?resize=768%2C459&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?resize=1536%2C919&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?ssl=1" data-lbwps-width="1567" data-lbwps-height="933" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9-1536x915.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19390" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?fit=1567%2C933&amp;ssl=1" data-orig-size="1567,933" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?fit=640%2C381&amp;ssl=1" class="aligncenter size-full wp-image-19390" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?resize=640%2C381&#038;ssl=1" alt="" width="640" height="381" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?w=1567&amp;ssl=1 1567w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?resize=595%2C354&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?resize=960%2C572&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?resize=768%2C457&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?resize=1536%2C915&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_9.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Vemos que ya tenemos la zona creada con nuestras dos interfaces WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?ssl=1" data-lbwps-width="1821" data-lbwps-height="387" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10-1536x326.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19391" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?fit=1821%2C387&amp;ssl=1" data-orig-size="1821,387" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?fit=640%2C136&amp;ssl=1" class="aligncenter size-full wp-image-19391" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?resize=640%2C136&#038;ssl=1" alt="" width="640" height="136" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?w=1821&amp;ssl=1 1821w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?resize=595%2C126&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?resize=960%2C204&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?resize=768%2C163&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?resize=1536%2C326&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos de nuevo a <strong>Network &gt; Interfaces</strong> podemos ver la interface virtual para la nueva zona SD-WAN y las interfaces que la componen (WAN1 y WAN2):</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?ssl=1" data-lbwps-width="1598" data-lbwps-height="789" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11-1536x758.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19392" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?fit=1598%2C789&amp;ssl=1" data-orig-size="1598,789" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?fit=640%2C316&amp;ssl=1" class="aligncenter size-full wp-image-19392" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?resize=640%2C316&#038;ssl=1" alt="" width="640" height="316" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?w=1598&amp;ssl=1 1598w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?resize=595%2C294&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?resize=960%2C474&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?resize=768%2C379&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?resize=1536%2C758&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_11.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>El siguiente paso será crearnos la ruta estática por defecto para la salida a Internet por la SD-WAN, para ello, accedemos a <strong>Network &gt; Static Routes &gt; Create new</strong> y creamos la ruta por defecto para la SD-WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?ssl=1" data-lbwps-width="1566" data-lbwps-height="936" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12-1536x918.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19393" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?fit=1566%2C936&amp;ssl=1" data-orig-size="1566,936" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?fit=640%2C383&amp;ssl=1" class="aligncenter size-full wp-image-19393" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?resize=640%2C383&#038;ssl=1" alt="" width="640" height="383" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?w=1566&amp;ssl=1 1566w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?resize=595%2C356&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?resize=960%2C574&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?resize=768%2C459&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?resize=1536%2C918&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_12.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos que ya la tenemos creada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?ssl=1" data-lbwps-width="1801" data-lbwps-height="358" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13-1536x305.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19394" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?fit=1801%2C358&amp;ssl=1" data-orig-size="1801,358" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?fit=640%2C127&amp;ssl=1" class="aligncenter size-full wp-image-19394" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?resize=640%2C127&#038;ssl=1" alt="" width="640" height="127" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?w=1801&amp;ssl=1 1801w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?resize=595%2C118&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?resize=960%2C191&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?resize=768%2C153&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?resize=1536%2C305&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_13.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para verificar que funciona, desde la CLI le hacemos un ping a google.com y vemos que ya recibimos respuesta:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png?ssl=1" data-lbwps-width="992" data-lbwps-height="378" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19395" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png?fit=992%2C378&amp;ssl=1" data-orig-size="992,378" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png?fit=640%2C244&amp;ssl=1" class="aligncenter size-full wp-image-19395" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png?resize=640%2C244&#038;ssl=1" alt="" width="640" height="244" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png?w=992&amp;ssl=1 992w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png?resize=595%2C227&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png?resize=960%2C366&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_14.png?resize=768%2C293&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Empezamos a ver tráfico sobre la SD-WAN, de momento sólo hay tráfico por la WAN1 ya que no tenemos configuradas las performance SLAs, entonces no estamos aplicando ningún tipo de balanceo, simplemente la interface WAN2 entrará a funcionar si la WAN1 cae, ahora más adelante configuraremos las performance SLAs:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?ssl=1" data-lbwps-width="1742" data-lbwps-height="391" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15-1536x345.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19396" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?fit=1742%2C391&amp;ssl=1" data-orig-size="1742,391" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?fit=640%2C143&amp;ssl=1" class="aligncenter size-full wp-image-19396" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?resize=640%2C144&#038;ssl=1" alt="" width="640" height="144" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?w=1742&amp;ssl=1 1742w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?resize=595%2C134&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?resize=960%2C215&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?resize=768%2C172&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?resize=1536%2C345&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_15.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a crear una política en el firewall para darle acceso web a todos los usuarios de nuestra red interna LAN a través de la SD-WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?ssl=1" data-lbwps-width="1356" data-lbwps-height="696" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19397" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?fit=1356%2C696&amp;ssl=1" data-orig-size="1356,696" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?fit=640%2C329&amp;ssl=1" class="aligncenter size-full wp-image-19397" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?resize=640%2C328&#038;ssl=1" alt="" width="640" height="328" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?w=1356&amp;ssl=1 1356w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?resize=595%2C305&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?resize=960%2C493&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?resize=768%2C394&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_16.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?ssl=1" data-lbwps-width="1361" data-lbwps-height="1079" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19398" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?fit=1361%2C1079&amp;ssl=1" data-orig-size="1361,1079" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?fit=640%2C507&amp;ssl=1" class="aligncenter size-full wp-image-19398" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?resize=640%2C507&#038;ssl=1" alt="" width="640" height="507" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?w=1361&amp;ssl=1 1361w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?resize=595%2C472&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?resize=960%2C761&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?resize=768%2C609&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_17.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí tenemos la política creada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="264" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18-1536x212.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19399" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?fit=1914%2C264&amp;ssl=1" data-orig-size="1914,264" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?fit=640%2C88&amp;ssl=1" class="aligncenter size-full wp-image-19399" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?resize=640%2C88&#038;ssl=1" alt="" width="640" height="88" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?resize=595%2C82&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?resize=960%2C132&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?resize=768%2C106&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?resize=1536%2C212&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_18.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a ver las Performance SLAs, accedemos a <strong>Network &gt; SD-WAN &gt; Performance SLAs</strong> y vemos que por defecto ya tenemos creadas algunas, con las Performance SLAs vamos a poder balancear por distintos criterios entre todas las interfaces miembros de la SD-WAN, estas performances SLAs que nos ha creado por defecto no tienen asignadas ninguna interface:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?ssl=1" data-lbwps-width="1912" data-lbwps-height="681" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19-1536x547.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19400" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?fit=1912%2C681&amp;ssl=1" data-orig-size="1912,681" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?fit=640%2C228&amp;ssl=1" class="aligncenter size-full wp-image-19400" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?resize=640%2C228&#038;ssl=1" alt="" width="640" height="228" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?w=1912&amp;ssl=1 1912w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?resize=595%2C212&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?resize=960%2C342&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?resize=768%2C274&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?resize=1536%2C547&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_19.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png?ssl=1" data-lbwps-width="1307" data-lbwps-height="936" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19401" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png?fit=1307%2C936&amp;ssl=1" data-orig-size="1307,936" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png?fit=640%2C458&amp;ssl=1" class="aligncenter size-full wp-image-19401" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png?resize=640%2C458&#038;ssl=1" alt="" width="640" height="458" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png?w=1307&amp;ssl=1 1307w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png?resize=595%2C426&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png?resize=960%2C687&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_20.png?resize=768%2C550&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En nuestro caso nos vamos a crear estas dos performances SLAs y las vamos a asociar a las dos interfaces WAN1 y WAN2 de nuestra SD-WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png?ssl=1" data-lbwps-width="1309" data-lbwps-height="1079" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19402" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png?fit=1309%2C1079&amp;ssl=1" data-orig-size="1309,1079" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png?fit=640%2C527&amp;ssl=1" class="aligncenter size-full wp-image-19402" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png?resize=640%2C528&#038;ssl=1" alt="" width="640" height="528" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png?w=1309&amp;ssl=1 1309w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png?resize=595%2C490&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png?resize=960%2C791&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_21.png?resize=768%2C633&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png?ssl=1" data-lbwps-width="1310" data-lbwps-height="1079" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19403" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png?fit=1310%2C1079&amp;ssl=1" data-orig-size="1310,1079" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png?fit=640%2C527&amp;ssl=1" class="aligncenter size-full wp-image-19403" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png?resize=640%2C527&#038;ssl=1" alt="" width="640" height="527" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png?w=1310&amp;ssl=1 1310w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png?resize=595%2C490&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png?resize=960%2C791&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_22.png?resize=768%2C633&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, aquí las tenemos ya creadas y configuradas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?ssl=1" data-lbwps-width="1912" data-lbwps-height="755" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23-1536x607.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19404" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?fit=1912%2C755&amp;ssl=1" data-orig-size="1912,755" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?fit=640%2C253&amp;ssl=1" class="aligncenter size-full wp-image-19404" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?resize=640%2C253&#038;ssl=1" alt="" width="640" height="253" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?w=1912&amp;ssl=1 1912w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?resize=595%2C235&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?resize=960%2C379&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?resize=768%2C303&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?resize=1536%2C607&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_23.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="771" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24-1536x619.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19405" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?fit=1914%2C771&amp;ssl=1" data-orig-size="1914,771" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?fit=640%2C258&amp;ssl=1" class="aligncenter size-full wp-image-19405" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?resize=640%2C258&#038;ssl=1" alt="" width="640" height="258" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?resize=595%2C240&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?resize=960%2C387&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?resize=768%2C309&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?resize=1536%2C619&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_24.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora si accedemos a nuestra zona SD-WAN, ya podemos ver que estamos realizando balanceo de carga, vemos que ya tenemos tráfico en ambas interfaces, no como antes, que todo estaba saliendo por la WAN1 y si fallaba ésta, entonces entraba en funcionamiento la WAN2:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?ssl=1" data-lbwps-width="1821" data-lbwps-height="386" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25-1536x326.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19406" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?fit=1821%2C386&amp;ssl=1" data-orig-size="1821,386" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?fit=640%2C135&amp;ssl=1" class="aligncenter size-full wp-image-19406" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?resize=640%2C136&#038;ssl=1" alt="" width="640" height="136" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?w=1821&amp;ssl=1 1821w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?resize=595%2C126&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?resize=960%2C203&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?resize=768%2C163&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?resize=1536%2C326&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_25.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Realmente el balanceo de carga se realiza a través de las reglas de SD-WAN, y por defecto, ya trae una regla implícita, que realiza un balanceo del 50% en cada interface, nosotros nos podemos ir creando reglas más específicas y configurar balanceos por ejemplo a sitios webs más específicos a través de estas reglas, esta sería la regla implícita por defecto:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?ssl=1" data-lbwps-width="1845" data-lbwps-height="331" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26-1536x276.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19407" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_26#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?fit=1845%2C331&amp;ssl=1" data-orig-size="1845,331" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_26" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?fit=640%2C115&amp;ssl=1" class="aligncenter size-full wp-image-19407" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?resize=640%2C115&#038;ssl=1" alt="" width="640" height="115" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?w=1845&amp;ssl=1 1845w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?resize=595%2C107&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?resize=960%2C172&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?resize=768%2C138&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?resize=1536%2C276&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_26.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para <strong>Source IP</strong>, el tráfico se divide a partes iguales entre los miembros, y las sesiones que comienzan en la misma dirección de origen utilizan la misma ruta:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?ssl=1" data-lbwps-width="1807" data-lbwps-height="608" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27-1536x517.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19408" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_27#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?fit=1807%2C608&amp;ssl=1" data-orig-size="1807,608" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_27" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?fit=640%2C215&amp;ssl=1" class="aligncenter size-full wp-image-19408" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?resize=640%2C215&#038;ssl=1" alt="" width="640" height="215" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?w=1807&amp;ssl=1 1807w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?resize=595%2C200&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?resize=960%2C323&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?resize=768%2C258&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?resize=1536%2C517&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_27.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para <strong>Sessions</strong>, el tráfico se distribuye en función del número de sesiones que se conectan a través del miembro:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?ssl=1" data-lbwps-width="1777" data-lbwps-height="955" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28-1536x825.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19409" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_28#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?fit=1777%2C955&amp;ssl=1" data-orig-size="1777,955" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_28" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?fit=640%2C344&amp;ssl=1" class="aligncenter size-full wp-image-19409" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?resize=640%2C344&#038;ssl=1" alt="" width="640" height="344" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?w=1777&amp;ssl=1 1777w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?resize=595%2C320&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?resize=960%2C516&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?resize=768%2C413&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?resize=1536%2C825&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_28.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para <strong>Spillover</strong>, el miembro de mayor prioridad se utiliza hasta que el ancho de banda supera los umbrales de entrada y salida, el tráfico adicional se envía a través del siguiente miembro SD-WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?ssl=1" data-lbwps-width="1784" data-lbwps-height="960" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29-1536x827.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19410" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_29#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?fit=1784%2C960&amp;ssl=1" data-orig-size="1784,960" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_29" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?fit=640%2C345&amp;ssl=1" class="aligncenter size-full wp-image-19410" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?resize=640%2C344&#038;ssl=1" alt="" width="640" height="344" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?w=1784&amp;ssl=1 1784w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?resize=595%2C320&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?resize=960%2C517&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?resize=768%2C413&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?resize=1536%2C827&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_29.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para <strong>Source-Destination IP</strong>, el tráfico se divide a partes iguales, las sesiones que empiezan en la misma dirección IP de origen y van a la misma dirección IP de destino utilizan la misma ruta:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?ssl=1" data-lbwps-width="1779" data-lbwps-height="701" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30-1536x605.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19411" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_30#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?fit=1779%2C701&amp;ssl=1" data-orig-size="1779,701" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_30" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?fit=640%2C252&amp;ssl=1" class="aligncenter size-full wp-image-19411" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?resize=640%2C252&#038;ssl=1" alt="" width="640" height="252" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?w=1779&amp;ssl=1 1779w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?resize=595%2C234&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?resize=960%2C378&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?resize=768%2C303&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?resize=1536%2C605&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_30.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para <strong>Volume</strong>, la carga de trabajo se distribuye en función del número de paquetes que pasan por el miembro:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?ssl=1" data-lbwps-width="1777" data-lbwps-height="932" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31-1536x806.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19412" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_31#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?fit=1777%2C932&amp;ssl=1" data-orig-size="1777,932" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_31" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?fit=640%2C336&amp;ssl=1" class="aligncenter size-full wp-image-19412" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?resize=640%2C336&#038;ssl=1" alt="" width="640" height="336" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?w=1777&amp;ssl=1 1777w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?resize=595%2C312&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?resize=960%2C504&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?resize=768%2C403&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?resize=1536%2C806&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_31.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Y estos serían los algoritmos de balanceo de carga utilizados para la regla implícita por defecto, con origen en todos (all) y destinos en todos (all).</li>
<li>Nosotros nos podemos crear reglas más específicas que se irán ubicando por encima de la regla implícita, teniendo así mayor prioridad, por ejemplo, nos vamos a crear una regla para el acceso a LinkedIn de los usuarios de nuestra LAN, para ello, accedemos a <strong>SD-WAN &gt; SD-WAN Rule:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?ssl=1" data-lbwps-width="1846" data-lbwps-height="327" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32-1536x272.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19413" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_32#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?fit=1846%2C327&amp;ssl=1" data-orig-size="1846,327" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_32" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?fit=640%2C113&amp;ssl=1" class="aligncenter size-full wp-image-19413" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?resize=640%2C113&#038;ssl=1" alt="" width="640" height="113" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?w=1846&amp;ssl=1 1846w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?resize=595%2C105&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?resize=960%2C170&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?resize=768%2C136&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?resize=1536%2C272&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_32.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Damos a <strong>Create new</strong>, dónde le asignamos un <strong>nombre</strong>, le indicamos el <strong>origen</strong>, que serán los equipos de nuestros usuarios, el <strong>destino</strong> que va a ser el servicio de internet LinkedIn-Web, le indicamos la estrategia del balanceo de carga a seguir, que será la que tenga mejor calidad con respecto al criterio de latencia utilizando uno de los performances SLAs que nos creamos anteriormente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png?ssl=1" data-lbwps-width="1134" data-lbwps-height="582" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19414" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_33#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png?fit=1134%2C582&amp;ssl=1" data-orig-size="1134,582" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_33" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png?fit=640%2C329&amp;ssl=1" class="aligncenter size-full wp-image-19414" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png?resize=640%2C328&#038;ssl=1" alt="" width="640" height="328" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png?w=1134&amp;ssl=1 1134w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png?resize=595%2C305&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png?resize=960%2C493&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_33.png?resize=768%2C394&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?ssl=1" data-lbwps-width="1375" data-lbwps-height="931" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19415" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_34#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?fit=1375%2C931&amp;ssl=1" data-orig-size="1375,931" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_34" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?fit=640%2C433&amp;ssl=1" class="aligncenter size-full wp-image-19415" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?resize=640%2C433&#038;ssl=1" alt="" width="640" height="433" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?w=1375&amp;ssl=1 1375w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?resize=595%2C403&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?resize=960%2C650&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?resize=768%2C520&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_34.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí tenemos la regla ya creada y operativa:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="328" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35-1536x263.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19416" data-permalink="https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/csdwaneff_35#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?fit=1913%2C328&amp;ssl=1" data-orig-size="1913,328" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdwaneff_35" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?fit=640%2C110&amp;ssl=1" class="aligncenter size-full wp-image-19416" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?resize=640%2C110&#038;ssl=1" alt="" width="640" height="110" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?resize=595%2C102&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?resize=960%2C165&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?resize=768%2C132&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?resize=1536%2C263&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2025/02/csdwaneff_35.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>A partir de aquí podemos ir ya configurando las reglas que nos vayan interesando y con los distintos balanceos de carga que nos vengan mejor.</li>
</ul>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/configuracion-sd-wan-en-firewall-fortigate/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19380</post-id>	</item>
		<item>
		<title>Configurar Web Proxy transparente en Firewall Fortigate</title>
		<link>https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate</link>
					<comments>https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 30 Dec 2024 11:28:11 +0000</pubDate>
				<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[TIC]]></category>
		<category><![CDATA[web proxy]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=19022</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo configurar un web proxy transparente en un firewall Fortigate, un proxy transparente es una combinación de un proxy con NAT para que las conexiones se enruten dentro del proxy y&#8230; <a href="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo configurar un web proxy transparente en un firewall Fortigate, un proxy transparente es una combinación de un proxy con NAT para que las conexiones se enruten dentro del proxy y el cliente no tenga que hacer ninguna configuración. En la mayoría de los casos en los que se emplea esta opción, el propio usuario desconoce que se esté utilizando un proxy.</p>
<ul>
<li>Para empezar, lo primero que vamos a realizar es habilitar en las características de nuestro firewall el Proxy Explícito, para ello accedemos a <strong>Sistema &gt; Visibilidad de Característica &gt; Funciones de seguridad y lo habilitamos</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?ssl=1" data-lbwps-width="1284" data-lbwps-height="898" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19023" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?fit=1284%2C898&amp;ssl=1" data-orig-size="1284,898" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?fit=640%2C447&amp;ssl=1" class="aligncenter size-full wp-image-19023" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?resize=640%2C448&#038;ssl=1" alt="" width="640" height="448" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?w=1284&amp;ssl=1 1284w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?resize=595%2C416&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?resize=960%2C671&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?resize=768%2C537&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_1.png?resize=250%2C175&amp;ssl=1 250w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo siguiente que vamos a realizar será editar una de nuestras políticas de salida a Internet:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?ssl=1" data-lbwps-width="1891" data-lbwps-height="455" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2-1536x370.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19024" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?fit=1891%2C455&amp;ssl=1" data-orig-size="1891,455" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?fit=640%2C154&amp;ssl=1" class="aligncenter size-full wp-image-19024" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?resize=640%2C154&#038;ssl=1" alt="" width="640" height="154" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?w=1891&amp;ssl=1 1891w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?resize=595%2C143&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?resize=960%2C231&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?resize=768%2C185&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?resize=1536%2C370&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_2.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En el <strong>Modo de inspección</strong>, lo configuraremos como <strong>Basado en Proxy</strong>, y aplicamos cambios:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_3.png?ssl=1" data-lbwps-width="827" data-lbwps-height="866" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19025" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_3.png?fit=827%2C866&amp;ssl=1" data-orig-size="827,866" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_3.png?fit=640%2C670&amp;ssl=1" class="aligncenter size-full wp-image-19025" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_3.png?resize=640%2C670&#038;ssl=1" alt="" width="640" height="670" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_3.png?w=827&amp;ssl=1 827w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_3.png?resize=595%2C623&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_3.png?resize=768%2C804&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png?ssl=1" data-lbwps-width="992" data-lbwps-height="261" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19026" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png?fit=992%2C261&amp;ssl=1" data-orig-size="992,261" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png?fit=640%2C169&amp;ssl=1" class="aligncenter size-full wp-image-19026" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png?resize=640%2C168&#038;ssl=1" alt="" width="640" height="168" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png?w=992&amp;ssl=1 992w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png?resize=595%2C157&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png?resize=960%2C253&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_4.png?resize=768%2C202&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Una vez aplicado el cambio, vamos a editar la política por la CLI:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="544" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5-1536x436.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19027" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?fit=1915%2C544&amp;ssl=1" data-orig-size="1915,544" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?fit=640%2C182&amp;ssl=1" class="aligncenter size-full wp-image-19027" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?resize=640%2C182&#038;ssl=1" alt="" width="640" height="182" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?resize=595%2C169&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?resize=960%2C273&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?resize=768%2C218&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?resize=1536%2C436&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_5.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Añadimos a la configuración <strong>set http-policy-redirect enable</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_6.png?ssl=1" data-lbwps-width="579" data-lbwps-height="880" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19028" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_6.png?fit=579%2C880&amp;ssl=1" data-orig-size="579,880" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_6.png?fit=579%2C880&amp;ssl=1" class="aligncenter size-full wp-image-19028" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_6.png?resize=579%2C880&#038;ssl=1" alt="" width="579" height="880" /></a></p>
<ul>
<li>Una vez introducido el comando, vemos que en la política ya nos aparece esta nueva opción:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png?ssl=1" data-lbwps-width="965" data-lbwps-height="642" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19029" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png?fit=965%2C642&amp;ssl=1" data-orig-size="965,642" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png?fit=640%2C426&amp;ssl=1" class="aligncenter size-full wp-image-19029" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png?resize=640%2C426&#038;ssl=1" alt="" width="640" height="426" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png?w=965&amp;ssl=1 965w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png?resize=595%2C396&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png?resize=960%2C639&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_7.png?resize=768%2C511&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Habilitamos también en la regla, <strong>Inspección SSL &gt; certificate-inspection</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png?ssl=1" data-lbwps-width="989" data-lbwps-height="553" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19030" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png?fit=989%2C553&amp;ssl=1" data-orig-size="989,553" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png?fit=640%2C358&amp;ssl=1" class="aligncenter size-full wp-image-19030" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png?resize=640%2C358&#038;ssl=1" alt="" width="640" height="358" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png?w=989&amp;ssl=1 989w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png?resize=595%2C333&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png?resize=960%2C537&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_8.png?resize=768%2C429&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora debemos acceder a <strong>Políticas y Objetos &gt; Política de Proxy</strong>, como podemos ver, nos ha creado una política implícita de DENY, denegándonos el acceso a cualquier sitio web:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?ssl=1" data-lbwps-width="1906" data-lbwps-height="356" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9-1536x287.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19031" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?fit=1906%2C356&amp;ssl=1" data-orig-size="1906,356" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?fit=640%2C119&amp;ssl=1" class="aligncenter size-full wp-image-19031" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?resize=640%2C120&#038;ssl=1" alt="" width="640" height="120" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?w=1906&amp;ssl=1 1906w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?resize=595%2C111&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?resize=960%2C179&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?resize=768%2C143&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?resize=1536%2C287&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_9.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora desde cualquier equipo de nuestra LAN se le va a denegar el acceso hacia internet:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?ssl=1" data-lbwps-width="1344" data-lbwps-height="700" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19032" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?fit=1344%2C700&amp;ssl=1" data-orig-size="1344,700" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?fit=640%2C333&amp;ssl=1" class="aligncenter size-full wp-image-19032" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?resize=640%2C333&#038;ssl=1" alt="" width="640" height="333" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?w=1344&amp;ssl=1 1344w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?resize=595%2C310&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?resize=960%2C500&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?resize=768%2C400&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<ul>
<li>Para habilitar la salida a Internet pasando por el web proxy, accedemos a <strong>Políticas y Objectos &gt; Política de Proxy &gt; Crear nuevo</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="314" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11-1536x252.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19033" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?fit=1913%2C314&amp;ssl=1" data-orig-size="1913,314" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?fit=640%2C105&amp;ssl=1" class="aligncenter size-full wp-image-19033" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?resize=640%2C105&#038;ssl=1" alt="" width="640" height="105" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?resize=595%2C98&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?resize=960%2C158&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?resize=768%2C126&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?resize=1536%2C252&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_11.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Nos creamos esta regla como web transparente, dónde le indicamos a nuestra LAN, que le permitimos la conexión hacia Internet, a través del web proxy:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png?ssl=1" data-lbwps-width="1247" data-lbwps-height="1041" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19034" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png?fit=1247%2C1041&amp;ssl=1" data-orig-size="1247,1041" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png?fit=640%2C534&amp;ssl=1" class="aligncenter size-full wp-image-19034" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png?resize=640%2C534&#038;ssl=1" alt="" width="640" height="534" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png?w=1247&amp;ssl=1 1247w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png?resize=595%2C497&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png?resize=960%2C801&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_12.png?resize=768%2C641&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí la tenemos creada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="306" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13-1536x246.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19035" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?fit=1914%2C306&amp;ssl=1" data-orig-size="1914,306" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?fit=640%2C102&amp;ssl=1" class="aligncenter size-full wp-image-19035" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?resize=640%2C102&#038;ssl=1" alt="" width="640" height="102" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?resize=595%2C95&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?resize=960%2C153&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?resize=768%2C123&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?resize=1536%2C246&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_13.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos a la misma web de antes, vemos que ya tenemos acceso:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?ssl=1" data-lbwps-width="1349" data-lbwps-height="644" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19036" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?fit=1349%2C644&amp;ssl=1" data-orig-size="1349,644" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?fit=640%2C305&amp;ssl=1" class="aligncenter size-full wp-image-19036" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?resize=640%2C306&#038;ssl=1" alt="" width="640" height="306" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?w=1349&amp;ssl=1 1349w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?resize=595%2C284&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?resize=960%2C458&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?resize=768%2C367&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_14.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora nos vamos a crear estos objetos de dirección, que son los que vamos a utilizar para denegar en las reglas las webs que nos interesen, <strong>Políticas y Objetos &gt; Dirección &gt; Crear nuevo &gt; Dirección</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_15.png?ssl=1" data-lbwps-width="617" data-lbwps-height="395" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19037" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_15.png?fit=617%2C395&amp;ssl=1" data-orig-size="617,395" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_15.png?fit=617%2C395&amp;ssl=1" class="aligncenter size-full wp-image-19037" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_15.png?resize=617%2C395&#038;ssl=1" alt="" width="617" height="395" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_15.png?w=617&amp;ssl=1 617w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_15.png?resize=595%2C381&amp;ssl=1 595w" sizes="auto, (max-width: 617px) 100vw, 617px" /></a></p>
<ul>
<li>Configuramos la categoría como <strong>Dirección de Proxy</strong>, le indicamos un <strong>Nombre</strong>, seleccionamos el patrón como <strong>Coincidencia de Expresión Regular de Host</strong>, y le ponemos el patrón que nos interese:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png?ssl=1" data-lbwps-width="1252" data-lbwps-height="675" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19038" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png?fit=1252%2C675&amp;ssl=1" data-orig-size="1252,675" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png?fit=640%2C345&amp;ssl=1" class="aligncenter size-full wp-image-19038" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png?resize=640%2C345&#038;ssl=1" alt="" width="640" height="345" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png?w=1252&amp;ssl=1 1252w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png?resize=595%2C321&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png?resize=960%2C518&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_16.png?resize=768%2C414&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Nos hemos creado estos objetos de dirección de proxy:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?ssl=1" data-lbwps-width="1529" data-lbwps-height="292" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19039" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?fit=1529%2C292&amp;ssl=1" data-orig-size="1529,292" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?fit=640%2C122&amp;ssl=1" class="aligncenter size-full wp-image-19039" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?resize=640%2C122&#038;ssl=1" alt="" width="640" height="122" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?w=1529&amp;ssl=1 1529w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?resize=595%2C114&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?resize=960%2C183&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?resize=768%2C147&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_17.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora nos vamos a crear esta regla para denegar la web o las webs que nos interesen, <strong>Políticas y Objectos &gt; Política de Proxy &gt; Crear nuevo</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?ssl=1" data-lbwps-width="1912" data-lbwps-height="330" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18-1536x265.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19040" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?fit=1912%2C330&amp;ssl=1" data-orig-size="1912,330" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?fit=640%2C111&amp;ssl=1" class="aligncenter size-full wp-image-19040" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?resize=640%2C110&#038;ssl=1" alt="" width="640" height="110" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?w=1912&amp;ssl=1 1912w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?resize=595%2C103&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?resize=960%2C166&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?resize=768%2C133&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?resize=1536%2C265&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_18.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En esta regla denegamos a nuestra LAN el acceso a las webs indicadas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png?ssl=1" data-lbwps-width="1249" data-lbwps-height="893" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19041" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png?fit=1249%2C893&amp;ssl=1" data-orig-size="1249,893" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png?fit=640%2C457&amp;ssl=1" class="aligncenter size-full wp-image-19041" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png?resize=640%2C458&#038;ssl=1" alt="" width="640" height="458" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png?w=1249&amp;ssl=1 1249w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png?resize=595%2C425&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png?resize=960%2C686&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_19.png?resize=768%2C549&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, aquí la tenemos, y la ubicamos por encima de la regla de permitir todo el acceso a Internet:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?ssl=1" data-lbwps-width="1912" data-lbwps-height="334" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20-1536x268.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19042" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?fit=1912%2C334&amp;ssl=1" data-orig-size="1912,334" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?fit=640%2C112&amp;ssl=1" class="aligncenter size-full wp-image-19042" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?resize=640%2C112&#038;ssl=1" alt="" width="640" height="112" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?w=1912&amp;ssl=1 1912w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?resize=595%2C104&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?resize=960%2C168&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?resize=768%2C134&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?resize=1536%2C268&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_20.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora si intentamos acceder a cualquiera de estas webs nos va a indicar que no es posible, que tenemos el acceso denegado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png?ssl=1" data-lbwps-width="1287" data-lbwps-height="693" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19043" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png?fit=1287%2C693&amp;ssl=1" data-orig-size="1287,693" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png?fit=640%2C345&amp;ssl=1" class="aligncenter size-full wp-image-19043" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png?resize=640%2C345&#038;ssl=1" alt="" width="640" height="345" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png?w=1287&amp;ssl=1 1287w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png?resize=595%2C320&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png?resize=960%2C517&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_21.png?resize=768%2C414&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Vemos que ya tenemos tráfico de denegación en nuestras reglas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?ssl=1" data-lbwps-width="1912" data-lbwps-height="323" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22-1536x259.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="19044" data-permalink="https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/cwpteff_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?fit=1912%2C323&amp;ssl=1" data-orig-size="1912,323" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cwpteff_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?fit=640%2C108&amp;ssl=1" class="aligncenter size-full wp-image-19044" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?resize=640%2C108&#038;ssl=1" alt="" width="640" height="108" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?w=1912&amp;ssl=1 1912w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?resize=595%2C101&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?resize=960%2C162&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?resize=768%2C130&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?resize=1536%2C259&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/cwpteff_22.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/configurar-web-proxy-transparente-en-firewall-fortigate/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19022</post-id>	</item>
		<item>
		<title>Configurar servidor DHCP Relay en Firewall Fortigate</title>
		<link>https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate</link>
					<comments>https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 18 Nov 2024 08:48:30 +0000</pubDate>
				<category><![CDATA[DHCP]]></category>
		<category><![CDATA[DHCP Relay]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=18917</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo configurar un servidor DHCP Relay en un firewall Fortigate, este DHCP relay va a escuchar las peticiones DHCP que se producen en la red, y las va a encaminar hacia&#8230; <a href="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo configurar un servidor DHCP Relay en un firewall Fortigate, este DHCP relay va a escuchar las peticiones DHCP que se producen en la red, y las va a encaminar hacia un servidor DHCP que se encuentra en otra red para que éste las atienda, el servidor DHCP dará una respuesta que enviará hacia el DHCP relay configurado en nuestro Fortigate, y éste la trasladará al cliente que hizo la petición.</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png?ssl=1" data-lbwps-width="1065" data-lbwps-height="604" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18918" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png?fit=1065%2C604&amp;ssl=1" data-orig-size="1065,604" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png?fit=640%2C363&amp;ssl=1" class="aligncenter size-full wp-image-18918" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png?resize=640%2C363&#038;ssl=1" alt="" width="640" height="363" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png?w=1065&amp;ssl=1 1065w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png?resize=595%2C337&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png?resize=960%2C544&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_1.png?resize=768%2C436&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para empezar, vamos a ver que tenemos configurado nuestro servidor DHCP con el ámbito de red que queremos asignar a nuestros equipos clientes, y estas serían las distintas configuraciones del ámbito:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_2.png?ssl=1" data-lbwps-width="710" data-lbwps-height="461" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18919" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_2.png?fit=710%2C461&amp;ssl=1" data-orig-size="710,461" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_2.png?fit=640%2C416&amp;ssl=1" class="aligncenter size-full wp-image-18919" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_2.png?resize=640%2C416&#038;ssl=1" alt="" width="640" height="416" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_2.png?w=710&amp;ssl=1 710w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_2.png?resize=595%2C386&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_3.png?ssl=1" data-lbwps-width="904" data-lbwps-height="469" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18920" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_3.png?fit=904%2C469&amp;ssl=1" data-orig-size="904,469" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_3.png?fit=640%2C332&amp;ssl=1" class="aligncenter size-full wp-image-18920" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_3.png?resize=640%2C332&#038;ssl=1" alt="" width="640" height="332" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_3.png?w=904&amp;ssl=1 904w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_3.png?resize=595%2C309&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_3.png?resize=768%2C398&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?ssl=1" data-lbwps-width="1038" data-lbwps-height="464" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18921" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?fit=1038%2C464&amp;ssl=1" data-orig-size="1038,464" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?fit=640%2C286&amp;ssl=1" class="aligncenter size-full wp-image-18921" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?resize=640%2C286&#038;ssl=1" alt="" width="640" height="286" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?w=1038&amp;ssl=1 1038w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?resize=595%2C266&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?resize=960%2C429&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?resize=768%2C343&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_4.png?resize=300%2C135&amp;ssl=1 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora en nuestro firewall fortigate vamos a acceder a <strong>Red &gt; Interfaces</strong> y editaremos la red dónde vamos a configurar nuestro servidor DHCP relay:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?ssl=1" data-lbwps-width="1374" data-lbwps-height="653" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18922" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?fit=1374%2C653&amp;ssl=1" data-orig-size="1374,653" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?fit=640%2C304&amp;ssl=1" class="aligncenter size-full wp-image-18922" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?resize=640%2C304&#038;ssl=1" alt="" width="640" height="304" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?w=1374&amp;ssl=1 1374w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?resize=595%2C283&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?resize=960%2C456&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?resize=768%2C365&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_5.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre la edición de la interface de red, vamos a habilitar el <strong>servidor DHCP </strong>y en Avanzado seleccionamos el modo Relay, tipo Regular y ponemos la IP del servidor DHCP dónde hemos configurado el ámbito para esta red, en este caso, he puesto dos servidores DHCP ya que en mi infraestructura tengo montado un failover cluster para este servicio con balaceo de carga 50%-50%:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png?ssl=1" data-lbwps-width="1256" data-lbwps-height="892" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18923" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png?fit=1256%2C892&amp;ssl=1" data-orig-size="1256,892" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png?fit=640%2C455&amp;ssl=1" class="aligncenter size-full wp-image-18923" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png?resize=640%2C455&#038;ssl=1" alt="" width="640" height="455" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png?w=1256&amp;ssl=1 1256w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png?resize=595%2C423&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png?resize=960%2C682&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_6.png?resize=768%2C545&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, ya lo tenemos configurado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?ssl=1" data-lbwps-width="1804" data-lbwps-height="614" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7-1536x523.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18924" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?fit=1804%2C614&amp;ssl=1" data-orig-size="1804,614" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?fit=640%2C218&amp;ssl=1" class="aligncenter size-full wp-image-18924" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?resize=640%2C218&#038;ssl=1" alt="" width="640" height="218" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?w=1804&amp;ssl=1 1804w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?resize=595%2C203&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?resize=960%2C327&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?resize=768%2C261&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?resize=1536%2C523&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_7.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora accedemos a una máquina cliente de nuestra infraestructura, y como podemos ver, ya se le está sirviendo el direccionamiento IP y las opciones del ámbito que hemos configurado, todo ello, a través del DHCP relay configurado en el fortigate:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png?ssl=1" data-lbwps-width="823" data-lbwps-height="580" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18925" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png?fit=823%2C580&amp;ssl=1" data-orig-size="823,580" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png?fit=640%2C451&amp;ssl=1" class="aligncenter size-full wp-image-18925" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png?resize=640%2C451&#038;ssl=1" alt="" width="640" height="451" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png?w=823&amp;ssl=1 823w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png?resize=595%2C419&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png?resize=768%2C541&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_8.png?resize=250%2C175&amp;ssl=1 250w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png?ssl=1" data-lbwps-width="1257" data-lbwps-height="642" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18926" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png?fit=1257%2C642&amp;ssl=1" data-orig-size="1257,642" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png?fit=640%2C327&amp;ssl=1" class="aligncenter size-full wp-image-18926" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png?resize=640%2C327&#038;ssl=1" alt="" width="640" height="327" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png?w=1257&amp;ssl=1 1257w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png?resize=595%2C304&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png?resize=960%2C490&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_9.png?resize=768%2C392&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En nuestra consola del servidor DHCP, podemos ver la concesión de direcciones para esta red:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?ssl=1" data-lbwps-width="1352" data-lbwps-height="370" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18927" data-permalink="https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/csdhcprelayeff_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?fit=1352%2C370&amp;ssl=1" data-orig-size="1352,370" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="csdhcprelayeff_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?fit=640%2C175&amp;ssl=1" class="aligncenter size-full wp-image-18927" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?resize=640%2C175&#038;ssl=1" alt="" width="640" height="175" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?w=1352&amp;ssl=1 1352w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?resize=595%2C163&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?resize=960%2C263&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?resize=768%2C210&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/11/csdhcprelayeff_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/configurar-servidor-dhcp-relay-en-firewall-fortigate/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18917</post-id>	</item>
		<item>
		<title>Bloquear conexiones VPN SSL desde ciertas IPs públicas en Firewall Fortigate</title>
		<link>https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate</link>
					<comments>https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 23 Sep 2024 06:47:44 +0000</pubDate>
				<category><![CDATA[Accesos remotos]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=18284</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo bloquear conexiones VPN SSL desde ciertas IPs públicas en un firewall Fortigate. En muchas ocasiones podemos ver en los logs de nuestros firewalls fortigate, que están intentando acceder a nuestra&#8230; <a href="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo bloquear conexiones VPN SSL desde ciertas IPs públicas en un firewall Fortigate.</p>
<ul>
<li>En muchas ocasiones podemos ver en los logs de nuestros firewalls fortigate, que están intentando acceder a nuestra conexión VPN SSL desde IPs sospechosas, en esta captura podemos ver intentos de sesión fallidos desde una IP y está intentando probar con distintos usuarios:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="886" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1-1536x711.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18285" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?fit=1913%2C886&amp;ssl=1" data-orig-size="1913,886" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?fit=640%2C297&amp;ssl=1" class="aligncenter size-full wp-image-18285" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?resize=640%2C296&#038;ssl=1" alt="" width="640" height="296" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?resize=595%2C276&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?resize=960%2C445&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?resize=768%2C356&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?resize=1536%2C711&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_1.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para bloquear a esta IP pública, lo primero que voy a realizar será crearme un grupo de direcciones llamado blacklistipp, dónde iré añadiendo todas las IPs públicas sospechosas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png?ssl=1" data-lbwps-width="1253" data-lbwps-height="621" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18286" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png?fit=1253%2C621&amp;ssl=1" data-orig-size="1253,621" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png?fit=640%2C317&amp;ssl=1" class="aligncenter size-full wp-image-18286" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png?resize=640%2C317&#038;ssl=1" alt="" width="640" height="317" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png?w=1253&amp;ssl=1 1253w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png?resize=595%2C295&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png?resize=960%2C476&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_2.png?resize=768%2C381&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Antes he creado los objetos de cada dirección IP pública, aquí muestro un ejemplo:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png?ssl=1" data-lbwps-width="1121" data-lbwps-height="405" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18287" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png?fit=1121%2C405&amp;ssl=1" data-orig-size="1121,405" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png?fit=640%2C231&amp;ssl=1" class="aligncenter size-full wp-image-18287" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png?resize=640%2C231&#038;ssl=1" alt="" width="640" height="231" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png?w=1121&amp;ssl=1 1121w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png?resize=595%2C215&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png?resize=960%2C347&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_3.png?resize=768%2C277&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Así nos quedaría:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?ssl=1" data-lbwps-width="1267" data-lbwps-height="569" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18288" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?fit=1267%2C569&amp;ssl=1" data-orig-size="1267,569" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?fit=640%2C287&amp;ssl=1" class="aligncenter size-full wp-image-18288" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?resize=640%2C287&#038;ssl=1" alt="" width="640" height="287" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?w=1267&amp;ssl=1 1267w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?resize=595%2C267&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?resize=960%2C431&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?resize=768%2C345&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_4.png?resize=300%2C135&amp;ssl=1 300w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para bloquear las conexiones VPN SSL a estas IPs públicas, accedemos a la consola de nuestro firewall y nos vamos a la configuración de la VPN SSL, con el comando <strong>config vpn ssl setting</strong>, una vez dentro de la configuración ejecutamos, <strong>set source-address «blacklistipp» </strong>y <strong>set source-address-negate enable</strong>, con el comando <strong>show</strong> podemos ver que la configuración se ha aplicado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_5.png?ssl=1" data-lbwps-width="575" data-lbwps-height="578" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18289" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_5.png?fit=575%2C578&amp;ssl=1" data-orig-size="575,578" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_5.png?fit=575%2C578&amp;ssl=1" class="aligncenter size-full wp-image-18289" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_5.png?resize=575%2C578&#038;ssl=1" alt="" width="575" height="578" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_5.png?w=575&amp;ssl=1 575w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_5.png?resize=50%2C50&amp;ssl=1 50w" sizes="auto, (max-width: 575px) 100vw, 575px" /></a></p>
<ul>
<li>Ahora, cuando un usuario intente conectarse desde una IP pública de la lista, la VPN SSL será rechazada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_6.png?ssl=1" data-lbwps-width="877" data-lbwps-height="524" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18290" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_6.png?fit=877%2C524&amp;ssl=1" data-orig-size="877,524" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_6.png?fit=640%2C382&amp;ssl=1" class="aligncenter size-full wp-image-18290" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_6.png?resize=640%2C382&#038;ssl=1" alt="" width="640" height="382" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_6.png?w=877&amp;ssl=1 877w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_6.png?resize=595%2C356&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_6.png?resize=768%2C459&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Es posible ver, que una de estas IPs públicas de la lista bloqueada está intentando conectarse, pero nuestro FortiGate no responde, para ello, ejecutamos el comando <strong>diagnose sniffer packet any «host 80.94.95.175 and port 10443» 4</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_7.png?ssl=1" data-lbwps-width="580" data-lbwps-height="246" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18291" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_7.png?fit=580%2C246&amp;ssl=1" data-orig-size="580,246" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_7.png?fit=580%2C246&amp;ssl=1" class="aligncenter size-full wp-image-18291" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_7.png?resize=580%2C246&#038;ssl=1" alt="" width="580" height="246" /></a></p>
<ul>
<li>Como podemos ver, si ejecutamos el comando, <strong>get vpn ssl monitor</strong>, se permitirá la conexión desde las IPs que no estén en la lista y se establecerán las conexiones:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_8.png?ssl=1" data-lbwps-width="667" data-lbwps-height="212" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18292" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_8.png?fit=667%2C212&amp;ssl=1" data-orig-size="667,212" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_8.png?fit=640%2C203&amp;ssl=1" class="aligncenter size-full wp-image-18292" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_8.png?resize=640%2C203&#038;ssl=1" alt="" width="640" height="203" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_8.png?w=667&amp;ssl=1 667w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_8.png?resize=595%2C189&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Otra forma de limitar el acceso, es irse a la <strong>Configuración de SSL_VPN &gt; Restringir Acceso</strong> y <strong>Limitar acceso a hosts específicos</strong>, dónde configuro la restricción para el grupo de IPs públicas bloqueadas, aquí el problema es que la conexión no se rechaza en una primera instancia, es decir, nos va a dejar introducir las credenciales y una vez introducidas bloquea la conexión, con el método visto anteriormente por consola, la conexión se rechaza desde primera hora:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png?ssl=1" data-lbwps-width="1236" data-lbwps-height="849" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18293" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png?fit=1236%2C849&amp;ssl=1" data-orig-size="1236,849" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png?fit=640%2C439&amp;ssl=1" class="aligncenter size-full wp-image-18293" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png?resize=640%2C440&#038;ssl=1" alt="" width="640" height="440" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png?w=1236&amp;ssl=1 1236w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png?resize=595%2C409&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png?resize=960%2C659&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/08/bcvpnssldcippeffg_9.png?resize=768%2C528&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li><a href="https://www.bujarra.com/protegiendonos-de-ataques-y-botnets-en-fortigate/" target="_blank" rel="noopener">Sobre este post realizado por mi compañero Héctor Herrero del blog Bujarra</a>, podemos aplicar las listas dinámicas que nos está indicando sobre la configuración de la VPN, quedando de esta manera:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="604" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10-1536x484.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18849" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?fit=1915%2C604&amp;ssl=1" data-orig-size="1915,604" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?fit=640%2C202&amp;ssl=1" class="aligncenter size-full wp-image-18849" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?resize=640%2C202&#038;ssl=1" alt="" width="640" height="202" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?resize=595%2C188&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?resize=960%2C303&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?resize=768%2C242&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?resize=1536%2C484&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png?ssl=1" data-lbwps-width="1234" data-lbwps-height="759" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18850" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png?fit=1234%2C759&amp;ssl=1" data-orig-size="1234,759" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png?fit=640%2C393&amp;ssl=1" class="aligncenter size-full wp-image-18850" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png?resize=640%2C394&#038;ssl=1" alt="" width="640" height="394" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png?w=1234&amp;ssl=1 1234w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png?resize=595%2C366&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png?resize=960%2C590&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_11.png?resize=768%2C472&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?ssl=1" data-lbwps-width="1424" data-lbwps-height="360" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="18851" data-permalink="https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/bcvpnssldcippeffg_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?fit=1424%2C360&amp;ssl=1" data-orig-size="1424,360" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="bcvpnssldcippeffg_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?fit=640%2C162&amp;ssl=1" class="aligncenter size-full wp-image-18851" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?resize=640%2C162&#038;ssl=1" alt="" width="640" height="162" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?w=1424&amp;ssl=1 1424w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?resize=595%2C150&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?resize=960%2C243&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?resize=768%2C194&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2024/09/bcvpnssldcippeffg_12.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/bloquear-conexiones-vpn-ssl-desde-ciertas-ips-publicas-en-firewall-fortigate/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18284</post-id>	</item>
		<item>
		<title>VPN site to site IPSEC entre Fortigate on-premise y OPNSense Azure</title>
		<link>https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure</link>
					<comments>https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 08 Jan 2024 10:35:34 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure Networking]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[OPNSense]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=17139</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo configurar una VPN site to site IPSEC entre un Fortigate on-premise y un OPNSense en Azure. La topología que vamos a utilizar será esta: Lo primero que vamos a realizar&#8230; <a href="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo configurar una VPN site to site IPSEC entre un Fortigate on-premise y un OPNSense en Azure.</p>
<p>La topología que vamos a utilizar será esta:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?ssl=1" data-lbwps-width="1227" data-lbwps-height="784" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17058" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-opnsense-en-azure/opnsense_topology_msaz#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?fit=1227%2C784&amp;ssl=1" data-orig-size="1227,784" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="OPNSense_topology_MSAZ" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?fit=640%2C409&amp;ssl=1" class="aligncenter size-full wp-image-17058" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?resize=640%2C409&#038;ssl=1" alt="" width="640" height="409" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?w=1227&amp;ssl=1 1227w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?resize=595%2C380&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?resize=960%2C613&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?resize=768%2C491&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo primero que vamos a realizar será acceder a nuestro Fortigate on-premise, y sobre <strong>VPN &gt; Túneles IPsec &gt; Crear nuevo &gt; IPsec Tunnel</strong>, empezaremos a crear el primer extremo de la VPN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png?ssl=1" data-lbwps-width="1300" data-lbwps-height="429" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17140" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png?fit=1300%2C429&amp;ssl=1" data-orig-size="1300,429" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png?fit=640%2C211&amp;ssl=1" class="aligncenter size-full wp-image-17140" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png?resize=640%2C211&#038;ssl=1" alt="" width="640" height="211" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png?w=1300&amp;ssl=1 1300w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png?resize=595%2C196&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png?resize=960%2C317&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_1.png?resize=768%2C253&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Configuración de VPN</strong> seleccionamos <strong>Personalizar</strong> y le indicamos un <strong>Nombre</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?ssl=1" data-lbwps-width="1348" data-lbwps-height="356" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17141" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?fit=1348%2C356&amp;ssl=1" data-orig-size="1348,356" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?fit=640%2C169&amp;ssl=1" class="aligncenter size-full wp-image-17141" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?resize=640%2C169&#038;ssl=1" alt="" width="640" height="169" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?w=1348&amp;ssl=1 1348w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?resize=595%2C157&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?resize=960%2C254&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?resize=768%2C203&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_2.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En la parte de <strong>Red</strong> configuramos la IP estática que tenemos asignada al OPNSense de Azure y la interface de salida:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_3.png?ssl=1" data-lbwps-width="914" data-lbwps-height="634" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17142" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_3.png?fit=914%2C634&amp;ssl=1" data-orig-size="914,634" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_3.png?fit=640%2C444&amp;ssl=1" class="aligncenter size-full wp-image-17142" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_3.png?resize=640%2C444&#038;ssl=1" alt="" width="640" height="444" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_3.png?w=914&amp;ssl=1 914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_3.png?resize=595%2C413&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_3.png?resize=768%2C533&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Autenticación</strong> le indicamos la Key compartida:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png?ssl=1" data-lbwps-width="1009" data-lbwps-height="291" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17143" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png?fit=1009%2C291&amp;ssl=1" data-orig-size="1009,291" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png?fit=640%2C185&amp;ssl=1" class="aligncenter size-full wp-image-17143" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png?resize=640%2C185&#038;ssl=1" alt="" width="640" height="185" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png?w=1009&amp;ssl=1 1009w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png?resize=595%2C172&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png?resize=960%2C277&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_4.png?resize=768%2C221&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos la <strong>fase 1</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_5.png?ssl=1" data-lbwps-width="910" data-lbwps-height="380" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17144" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_5.png?fit=910%2C380&amp;ssl=1" data-orig-size="910,380" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_5.png?fit=640%2C267&amp;ssl=1" class="aligncenter size-full wp-image-17144" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_5.png?resize=640%2C267&#038;ssl=1" alt="" width="640" height="267" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_5.png?w=910&amp;ssl=1 910w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_5.png?resize=595%2C248&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_5.png?resize=768%2C321&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos la <strong>fase2</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png?ssl=1" data-lbwps-width="1232" data-lbwps-height="888" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17145" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png?fit=1232%2C888&amp;ssl=1" data-orig-size="1232,888" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png?fit=640%2C461&amp;ssl=1" class="aligncenter size-full wp-image-17145" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png?resize=640%2C461&#038;ssl=1" alt="" width="640" height="461" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png?w=1232&amp;ssl=1 1232w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png?resize=595%2C429&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png?resize=960%2C692&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_6.png?resize=768%2C554&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, ya tenemos el primer extremo de la VPN configurado, el de la parte on-premise:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?ssl=1" data-lbwps-width="1653" data-lbwps-height="351" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7-1536x326.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17146" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?fit=1653%2C351&amp;ssl=1" data-orig-size="1653,351" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?fit=640%2C136&amp;ssl=1" class="aligncenter size-full wp-image-17146" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?resize=640%2C136&#038;ssl=1" alt="" width="640" height="136" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?w=1653&amp;ssl=1 1653w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?resize=595%2C126&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?resize=960%2C204&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?resize=768%2C163&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?resize=1536%2C326&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_7.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a crear las <strong>políticas</strong>:</li>
</ul>
<ul>
<li>Accedemos a <strong>Políticas y objetos&gt; Política IPv4 &gt; Crear nuevo</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_8.png?ssl=1" data-lbwps-width="952" data-lbwps-height="439" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17147" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_8.png?fit=952%2C439&amp;ssl=1" data-orig-size="952,439" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_8.png?fit=640%2C295&amp;ssl=1" class="aligncenter size-full wp-image-17147" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_8.png?resize=640%2C295&#038;ssl=1" alt="" width="640" height="295" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_8.png?w=952&amp;ssl=1 952w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_8.png?resize=595%2C274&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_8.png?resize=768%2C354&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Creamos una política para la conexión de sitio a sitio que permita el tráfico saliente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png?ssl=1" data-lbwps-width="1237" data-lbwps-height="1040" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17148" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png?fit=1237%2C1040&amp;ssl=1" data-orig-size="1237,1040" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png?fit=640%2C538&amp;ssl=1" class="aligncenter size-full wp-image-17148" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png?resize=640%2C538&#038;ssl=1" alt="" width="640" height="538" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png?w=1237&amp;ssl=1 1237w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png?resize=595%2C500&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png?resize=960%2C807&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_9.png?resize=768%2C646&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Creamos otra política para la conexión de sitio a sitio que permita el tráfico entrante:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png?ssl=1" data-lbwps-width="1245" data-lbwps-height="1039" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17149" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png?fit=1245%2C1039&amp;ssl=1" data-orig-size="1245,1039" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png?fit=640%2C534&amp;ssl=1" class="aligncenter size-full wp-image-17149" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png?resize=640%2C534&#038;ssl=1" alt="" width="640" height="534" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png?w=1245&amp;ssl=1 1245w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png?resize=595%2C497&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png?resize=960%2C801&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_10.png?resize=768%2C641&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí podemos ver las políticas creadas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="667" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11-1536x535.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17150" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?fit=1915%2C667&amp;ssl=1" data-orig-size="1915,667" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?fit=640%2C223&amp;ssl=1" class="aligncenter size-full wp-image-17150" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?resize=640%2C223&#038;ssl=1" alt="" width="640" height="223" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?resize=595%2C207&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?resize=960%2C334&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?resize=768%2C267&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?resize=1536%2C535&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_11.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora creamos la ruta estática hacia Azure:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png?ssl=1" data-lbwps-width="1273" data-lbwps-height="511" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17151" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png?fit=1273%2C511&amp;ssl=1" data-orig-size="1273,511" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png?fit=640%2C257&amp;ssl=1" class="aligncenter size-full wp-image-17151" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png?resize=640%2C257&#038;ssl=1" alt="" width="640" height="257" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png?w=1273&amp;ssl=1 1273w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png?resize=595%2C239&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png?resize=960%2C385&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_12.png?resize=768%2C308&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?ssl=1" data-lbwps-width="1775" data-lbwps-height="412" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13-1536x357.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17152" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?fit=1775%2C412&amp;ssl=1" data-orig-size="1775,412" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?fit=640%2C149&amp;ssl=1" class="aligncenter size-full wp-image-17152" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?resize=640%2C149&#038;ssl=1" alt="" width="640" height="149" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?w=1775&amp;ssl=1 1775w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?resize=595%2C138&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?resize=960%2C223&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?resize=768%2C178&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?resize=1536%2C357&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_13.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo segundo que vamos a realizar será acceder a nuestro OPNSense en Azure, y sobre <strong>Firewall &gt; WAN &gt; +</strong>, nos crearemos tres reglas de firewall para permitir el tráfico IPSEC a la interfaz WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="455" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14-1536x365.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17153" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?fit=1914%2C455&amp;ssl=1" data-orig-size="1914,455" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?fit=640%2C152&amp;ssl=1" class="aligncenter size-full wp-image-17153" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?resize=640%2C152&#038;ssl=1" alt="" width="640" height="152" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?resize=595%2C141&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?resize=960%2C228&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?resize=768%2C183&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?resize=1536%2C365&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_14.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Regla para IPSec ESP:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="434" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15-1536x348.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17154" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?fit=1914%2C434&amp;ssl=1" data-orig-size="1914,434" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?fit=640%2C145&amp;ssl=1" class="aligncenter size-full wp-image-17154" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?resize=640%2C145&#038;ssl=1" alt="" width="640" height="145" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?resize=595%2C135&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?resize=960%2C218&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?resize=768%2C174&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?resize=1536%2C348&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_15.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?ssl=1" data-lbwps-width="1503" data-lbwps-height="686" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17155" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?fit=1503%2C686&amp;ssl=1" data-orig-size="1503,686" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?fit=640%2C292&amp;ssl=1" class="aligncenter size-full wp-image-17155" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?resize=640%2C292&#038;ssl=1" alt="" width="640" height="292" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?w=1503&amp;ssl=1 1503w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?resize=595%2C272&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?resize=960%2C438&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?resize=768%2C351&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_16.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?ssl=1" data-lbwps-width="1477" data-lbwps-height="821" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17156" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?fit=1477%2C821&amp;ssl=1" data-orig-size="1477,821" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?fit=640%2C356&amp;ssl=1" class="aligncenter size-full wp-image-17156" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?resize=640%2C356&#038;ssl=1" alt="" width="640" height="356" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?w=1477&amp;ssl=1 1477w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?resize=595%2C331&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?resize=960%2C534&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?resize=768%2C427&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_17.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Regla para IPSec ISAKMP puerto 500:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="548" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18-1536x440.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17157" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?fit=1915%2C548&amp;ssl=1" data-orig-size="1915,548" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?fit=640%2C183&amp;ssl=1" class="aligncenter size-full wp-image-17157" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?resize=640%2C183&#038;ssl=1" alt="" width="640" height="183" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?resize=595%2C170&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?resize=960%2C275&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?resize=768%2C220&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?resize=1536%2C440&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_18.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?ssl=1" data-lbwps-width="1499" data-lbwps-height="687" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17158" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?fit=1499%2C687&amp;ssl=1" data-orig-size="1499,687" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?fit=640%2C293&amp;ssl=1" class="aligncenter size-full wp-image-17158" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?resize=640%2C293&#038;ssl=1" alt="" width="640" height="293" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?w=1499&amp;ssl=1 1499w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?resize=595%2C273&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?resize=960%2C440&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?resize=768%2C352&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_19.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?ssl=1" data-lbwps-width="1479" data-lbwps-height="827" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17159" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?fit=1479%2C827&amp;ssl=1" data-orig-size="1479,827" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?fit=640%2C358&amp;ssl=1" class="aligncenter size-full wp-image-17159" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?resize=640%2C358&#038;ssl=1" alt="" width="640" height="358" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?w=1479&amp;ssl=1 1479w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?resize=595%2C333&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?resize=960%2C537&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?resize=768%2C429&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_20.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Regla para IPSec NAT-T puerto 4500:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="558" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23-1536x448.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17160" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?fit=1913%2C558&amp;ssl=1" data-orig-size="1913,558" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?fit=640%2C187&amp;ssl=1" class="aligncenter size-full wp-image-17160" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?resize=640%2C187&#038;ssl=1" alt="" width="640" height="187" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?resize=595%2C174&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?resize=960%2C280&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?resize=768%2C224&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?resize=1536%2C448&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_23.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?ssl=1" data-lbwps-width="1481" data-lbwps-height="684" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17161" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?fit=1481%2C684&amp;ssl=1" data-orig-size="1481,684" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?fit=640%2C295&amp;ssl=1" class="aligncenter size-full wp-image-17161" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?resize=640%2C296&#038;ssl=1" alt="" width="640" height="296" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?w=1481&amp;ssl=1 1481w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?resize=595%2C275&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?resize=960%2C443&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?resize=768%2C355&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_24.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?ssl=1" data-lbwps-width="1482" data-lbwps-height="837" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17162" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?fit=1482%2C837&amp;ssl=1" data-orig-size="1482,837" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?fit=640%2C361&amp;ssl=1" class="aligncenter size-full wp-image-17162" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?resize=640%2C361&#038;ssl=1" alt="" width="640" height="361" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?w=1482&amp;ssl=1 1482w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?resize=595%2C336&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?resize=960%2C542&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?resize=768%2C434&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_25.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver aquí tenemos las tres reglas creadas en la interface WAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="554" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26-1536x445.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17163" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_26#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?fit=1913%2C554&amp;ssl=1" data-orig-size="1913,554" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_26" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?fit=640%2C185&amp;ssl=1" class="aligncenter size-full wp-image-17163" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?resize=640%2C185&#038;ssl=1" alt="" width="640" height="185" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?resize=595%2C172&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?resize=960%2C278&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?resize=768%2C222&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?resize=1536%2C445&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_26.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a configurar la fase 1 de la VPN site to site, para ello, accedemos a <strong>VPN &gt; IPSec &gt; Connections &gt; Tunnel Settings (legacy) &gt; +</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="570" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27-1536x457.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17164" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_27#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?fit=1914%2C570&amp;ssl=1" data-orig-size="1914,570" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_27" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?fit=640%2C191&amp;ssl=1" class="aligncenter size-full wp-image-17164" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?resize=640%2C191&#038;ssl=1" alt="" width="640" height="191" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?resize=595%2C177&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?resize=960%2C286&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?resize=768%2C229&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?resize=1536%2C457&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_27.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png?ssl=1" data-lbwps-width="1099" data-lbwps-height="568" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17165" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_28#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png?fit=1099%2C568&amp;ssl=1" data-orig-size="1099,568" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_28" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png?fit=640%2C331&amp;ssl=1" class="aligncenter size-full wp-image-17165" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png?resize=640%2C331&#038;ssl=1" alt="" width="640" height="331" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png?w=1099&amp;ssl=1 1099w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png?resize=595%2C308&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png?resize=960%2C496&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_28.png?resize=768%2C397&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png?ssl=1" data-lbwps-width="1099" data-lbwps-height="423" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17166" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_29#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png?fit=1099%2C423&amp;ssl=1" data-orig-size="1099,423" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_29" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png?fit=640%2C246&amp;ssl=1" class="aligncenter size-full wp-image-17166" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png?resize=640%2C246&#038;ssl=1" alt="" width="640" height="246" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png?w=1099&amp;ssl=1 1099w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png?resize=595%2C229&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png?resize=960%2C369&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_29.png?resize=768%2C296&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png?ssl=1" data-lbwps-width="1141" data-lbwps-height="753" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17167" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_30#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png?fit=1141%2C753&amp;ssl=1" data-orig-size="1141,753" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_30" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png?fit=640%2C423&amp;ssl=1" class="aligncenter size-full wp-image-17167" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png?resize=640%2C422&#038;ssl=1" alt="" width="640" height="422" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png?w=1141&amp;ssl=1 1141w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png?resize=595%2C393&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png?resize=960%2C634&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_30.png?resize=768%2C507&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png?ssl=1" data-lbwps-width="1137" data-lbwps-height="815" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17168" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_31#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png?fit=1137%2C815&amp;ssl=1" data-orig-size="1137,815" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_31" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png?fit=640%2C459&amp;ssl=1" class="aligncenter size-full wp-image-17168" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png?resize=640%2C459&#038;ssl=1" alt="" width="640" height="459" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png?w=1137&amp;ssl=1 1137w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png?resize=595%2C426&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png?resize=960%2C688&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_31.png?resize=768%2C551&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, ya tenemos la fase 1 creada, habilitamos IPSec y aplicamos los cambios:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="714" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32-1536x573.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17169" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_32#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?fit=1914%2C714&amp;ssl=1" data-orig-size="1914,714" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_32" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?fit=640%2C239&amp;ssl=1" class="aligncenter size-full wp-image-17169" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?resize=640%2C239&#038;ssl=1" alt="" width="640" height="239" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?resize=595%2C222&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?resize=960%2C358&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?resize=768%2C286&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?resize=1536%2C573&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_32.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a configurar la fase 2 de la VPN site to site, para ello, accedemos a <strong>VPN &gt; IPSec &gt; Connections &gt; Tunnel Settings (legacy) &gt; +:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="399" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33-1536x320.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17170" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_33#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?fit=1914%2C399&amp;ssl=1" data-orig-size="1914,399" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_33" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?fit=640%2C133&amp;ssl=1" class="aligncenter size-full wp-image-17170" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?resize=640%2C133&#038;ssl=1" alt="" width="640" height="133" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?resize=595%2C124&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?resize=960%2C200&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?resize=768%2C160&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?resize=1536%2C320&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_33.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png?ssl=1" data-lbwps-width="1114" data-lbwps-height="594" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17171" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_34#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png?fit=1114%2C594&amp;ssl=1" data-orig-size="1114,594" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_34" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png?fit=640%2C341&amp;ssl=1" class="aligncenter size-full wp-image-17171" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png?resize=640%2C341&#038;ssl=1" alt="" width="640" height="341" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png?w=1114&amp;ssl=1 1114w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png?resize=595%2C317&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png?resize=960%2C512&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_34.png?resize=768%2C410&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png?ssl=1" data-lbwps-width="1213" data-lbwps-height="813" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17172" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_35#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png?fit=1213%2C813&amp;ssl=1" data-orig-size="1213,813" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_35" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png?fit=640%2C429&amp;ssl=1" class="aligncenter size-full wp-image-17172" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png?resize=640%2C429&#038;ssl=1" alt="" width="640" height="429" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png?w=1213&amp;ssl=1 1213w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png?resize=595%2C399&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png?resize=960%2C643&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_35.png?resize=768%2C515&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aplicamos los cambios:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="702" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36-1536x563.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17173" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_36#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?fit=1914%2C702&amp;ssl=1" data-orig-size="1914,702" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_36" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?fit=640%2C235&amp;ssl=1" class="aligncenter size-full wp-image-17173" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?resize=640%2C235&#038;ssl=1" alt="" width="640" height="235" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?resize=595%2C218&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?resize=960%2C352&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?resize=768%2C282&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?resize=1536%2C563&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_36.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, ya tenemos la fase 2 de la VPN site to site configurada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="665" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37-1536x534.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17174" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_37#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?fit=1913%2C665&amp;ssl=1" data-orig-size="1913,665" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_37" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?fit=640%2C223&amp;ssl=1" class="aligncenter size-full wp-image-17174" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?resize=640%2C222&#038;ssl=1" alt="" width="640" height="222" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?resize=595%2C207&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?resize=960%2C334&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?resize=768%2C267&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?resize=1536%2C534&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_37.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para terminar, vamos a crear dos políticas, una de entrada y otra de salida para comunicar las dos subredes que tenemos, una en Azure y otra On-premise, para ello, accedemos a <strong>Firewall &gt; Rules &gt; IPSec &gt; +</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="424" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38-1536x340.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17175" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_38#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?fit=1913%2C424&amp;ssl=1" data-orig-size="1913,424" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_38" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?fit=640%2C142&amp;ssl=1" class="aligncenter size-full wp-image-17175" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?resize=640%2C142&#038;ssl=1" alt="" width="640" height="142" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?resize=595%2C132&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?resize=960%2C213&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?resize=768%2C170&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?resize=1536%2C340&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_38.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Regla de entrada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="429" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39-1536x344.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17176" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_39#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?fit=1915%2C429&amp;ssl=1" data-orig-size="1915,429" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_39" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?fit=640%2C143&amp;ssl=1" class="aligncenter size-full wp-image-17176" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?resize=640%2C143&#038;ssl=1" alt="" width="640" height="143" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?resize=595%2C133&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?resize=960%2C215&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?resize=768%2C172&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?resize=1536%2C344&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_39.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?ssl=1" data-lbwps-width="1492" data-lbwps-height="689" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17177" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_40#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?fit=1492%2C689&amp;ssl=1" data-orig-size="1492,689" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_40" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?fit=640%2C295&amp;ssl=1" class="aligncenter size-full wp-image-17177" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?resize=640%2C296&#038;ssl=1" alt="" width="640" height="296" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?w=1492&amp;ssl=1 1492w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?resize=595%2C275&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?resize=960%2C443&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?resize=768%2C355&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_40.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?ssl=1" data-lbwps-width="1487" data-lbwps-height="806" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17178" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_41#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?fit=1487%2C806&amp;ssl=1" data-orig-size="1487,806" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_41" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?fit=640%2C347&amp;ssl=1" class="aligncenter size-full wp-image-17178" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?resize=640%2C347&#038;ssl=1" alt="" width="640" height="347" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?w=1487&amp;ssl=1 1487w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?resize=595%2C323&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?resize=960%2C520&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?resize=768%2C416&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_41.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Regla de salida:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="475" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42-1536x381.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17179" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_42#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?fit=1915%2C475&amp;ssl=1" data-orig-size="1915,475" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_42" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?fit=640%2C159&amp;ssl=1" class="aligncenter size-full wp-image-17179" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?resize=640%2C159&#038;ssl=1" alt="" width="640" height="159" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?resize=595%2C148&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?resize=960%2C238&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?resize=768%2C190&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?resize=1536%2C381&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_42.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?ssl=1" data-lbwps-width="1490" data-lbwps-height="690" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17180" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_43#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?fit=1490%2C690&amp;ssl=1" data-orig-size="1490,690" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_43" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?fit=640%2C297&amp;ssl=1" class="aligncenter size-full wp-image-17180" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?resize=640%2C296&#038;ssl=1" alt="" width="640" height="296" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?w=1490&amp;ssl=1 1490w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?resize=595%2C276&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?resize=960%2C445&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?resize=768%2C356&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_43.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?ssl=1" data-lbwps-width="1480" data-lbwps-height="823" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17181" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_44#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?fit=1480%2C823&amp;ssl=1" data-orig-size="1480,823" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_44" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?fit=640%2C356&amp;ssl=1" class="aligncenter size-full wp-image-17181" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?resize=640%2C356&#038;ssl=1" alt="" width="640" height="356" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?w=1480&amp;ssl=1 1480w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?resize=595%2C331&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?resize=960%2C534&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?resize=768%2C427&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_44.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos las dos reglas creadas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="401" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45-1536x322.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17182" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_45#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?fit=1914%2C401&amp;ssl=1" data-orig-size="1914,401" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_45" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?fit=640%2C134&amp;ssl=1" class="aligncenter size-full wp-image-17182" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?resize=640%2C134&#038;ssl=1" alt="" width="640" height="134" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?resize=595%2C125&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?resize=960%2C201&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?resize=768%2C161&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?resize=1536%2C322&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_45.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>A continuación, sobre <strong>Firewall &gt; Rules &gt; LAN</strong> vamos a crear esta regla para permitir el tráfico entre la subred de Azure y la subred on-premise:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="662" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46-1536x531.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17183" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_46#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?fit=1914%2C662&amp;ssl=1" data-orig-size="1914,662" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_46" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?fit=640%2C221&amp;ssl=1" class="aligncenter size-full wp-image-17183" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?resize=640%2C221&#038;ssl=1" alt="" width="640" height="221" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?resize=595%2C206&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?resize=960%2C332&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?resize=768%2C266&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?resize=1536%2C531&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_46.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?ssl=1" data-lbwps-width="1508" data-lbwps-height="684" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17184" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_47#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?fit=1508%2C684&amp;ssl=1" data-orig-size="1508,684" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_47" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?fit=640%2C290&amp;ssl=1" class="aligncenter size-full wp-image-17184" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?resize=640%2C290&#038;ssl=1" alt="" width="640" height="290" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?w=1508&amp;ssl=1 1508w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?resize=595%2C270&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?resize=960%2C435&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?resize=768%2C348&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?resize=300%2C135&amp;ssl=1 300w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_47.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?ssl=1" data-lbwps-width="1522" data-lbwps-height="820" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17185" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_48#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?fit=1522%2C820&amp;ssl=1" data-orig-size="1522,820" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_48" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?fit=640%2C345&amp;ssl=1" class="aligncenter size-full wp-image-17185" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?resize=640%2C345&#038;ssl=1" alt="" width="640" height="345" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?w=1522&amp;ssl=1 1522w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?resize=595%2C321&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?resize=960%2C517&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?resize=768%2C414&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_48.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, ya tenemos el túnel IPSEC levantado.</li>
<li>Fortigate On-premise:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?ssl=1" data-lbwps-width="1657" data-lbwps-height="379" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49-1536x351.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17186" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_49#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?fit=1657%2C379&amp;ssl=1" data-orig-size="1657,379" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_49" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?fit=640%2C147&amp;ssl=1" class="aligncenter size-full wp-image-17186" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?resize=640%2C146&#038;ssl=1" alt="" width="640" height="146" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?w=1657&amp;ssl=1 1657w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?resize=595%2C136&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?resize=960%2C220&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?resize=768%2C176&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?resize=1536%2C351&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_49.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>OPNSense Azure:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="562" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50-1536x451.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17187" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_50#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?fit=1915%2C562&amp;ssl=1" data-orig-size="1915,562" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_50" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?fit=640%2C188&amp;ssl=1" class="aligncenter size-full wp-image-17187" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?resize=640%2C188&#038;ssl=1" alt="" width="640" height="188" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?resize=595%2C175&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?resize=960%2C282&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?resize=768%2C225&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?resize=1536%2C451&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_50.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para verificar que todo funciona correctamente vamos a realizar un ping desde una máquina on-premise a una máquina en Azure y viceversa:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?ssl=1" data-lbwps-width="1774" data-lbwps-height="651" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51-1536x564.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17188" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_51#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?fit=1774%2C651&amp;ssl=1" data-orig-size="1774,651" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_51" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?fit=640%2C235&amp;ssl=1" class="aligncenter size-full wp-image-17188" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?resize=640%2C235&#038;ssl=1" alt="" width="640" height="235" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?w=1774&amp;ssl=1 1774w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?resize=595%2C218&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?resize=960%2C352&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?resize=768%2C282&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?resize=1536%2C564&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_51.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png?ssl=1" data-lbwps-width="1000" data-lbwps-height="614" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17189" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_52#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png?fit=1000%2C614&amp;ssl=1" data-orig-size="1000,614" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_52" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png?fit=640%2C393&amp;ssl=1" class="aligncenter size-full wp-image-17189" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png?resize=640%2C393&#038;ssl=1" alt="" width="640" height="393" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png?w=1000&amp;ssl=1 1000w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png?resize=595%2C365&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png?resize=960%2C589&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_52.png?resize=768%2C472&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_53.png?ssl=1" data-lbwps-width="679" data-lbwps-height="523" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_53.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17190" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/vstsefopyopsaz_53#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_53.png?fit=679%2C523&amp;ssl=1" data-orig-size="679,523" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsefopyopsaz_53" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_53.png?fit=640%2C493&amp;ssl=1" class="aligncenter size-full wp-image-17190" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_53.png?resize=640%2C493&#038;ssl=1" alt="" width="640" height="493" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_53.png?w=679&amp;ssl=1 679w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/vstsefopyopsaz_53.png?resize=595%2C458&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure/feed</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">17139</post-id>	</item>
		<item>
		<title>Despliegue y configuración de firewall OPNSense en Azure</title>
		<link>https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-opnsense-en-azure</link>
					<comments>https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-opnsense-en-azure#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 04 Dec 2023 11:46:02 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure Networking]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[OPNSense]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=17053</guid>

					<description><![CDATA[Hola a tod@s, En estos posts vamos a ver cómo desplegar y configurar un firewall OPNSense en Azure. La topología que vamos a utilizar será esta: &#160; Este post lo vamos a dividir en: Despliegue Firewall OPNSense en Azure Desplegar&#8230; <a href="https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-opnsense-en-azure" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En estos posts vamos a ver cómo desplegar y configurar un firewall OPNSense en Azure.</p>
<p>La topología que vamos a utilizar será esta:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?ssl=1" data-lbwps-width="1227" data-lbwps-height="784" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="17058" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-opnsense-en-azure/opnsense_topology_msaz#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?fit=1227%2C784&amp;ssl=1" data-orig-size="1227,784" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="OPNSense_topology_MSAZ" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?fit=640%2C409&amp;ssl=1" class="aligncenter size-full wp-image-17058" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?resize=640%2C409&#038;ssl=1" alt="" width="640" height="409" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?w=1227&amp;ssl=1 1227w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?resize=595%2C380&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?resize=960%2C613&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/12/OPNSense_topology_MSAZ.png?resize=768%2C491&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Este post lo vamos a dividir en:</p>
<ul>
<li><a href="https://blog.ragasys.es/despliegue-firewall-opnsense-en-azure" target="_blank" rel="noopener">Despliegue Firewall OPNSense en Azure</a></li>
<li><a href="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-udr-en-azure" target="_blank" rel="noopener">Desplegar y configurar tabla de rutas UDR en Azure</a></li>
<li><a href="https://blog.ragasys.es/configuracion-inicial-y-avanzada-opnsense" target="_blank" rel="noopener">Configuración inicial y avanzada OPNSense</a></li>
<li><a href="https://blog.ragasys.es/opnsense-configurar-categorias-y-alias" target="_blank" rel="noopener">Configurar Categorías y Alias</a></li>
<li><a href="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-opnsense-azure" target="_blank" rel="noopener">VPN site to site IPSEC entre Fortigate on-premise y OPNSense Azure</a></li>
<li><a href="https://blog.ragasys.es/configurar-servidor-ldap-en-opnsense" target="_blank" rel="noopener">Configurar servidor LDAP en OPNSense</a></li>
<li><a href="https://blog.ragasys.es/acceso-administracion-web-y-ssh-opnsense" target="_blank" rel="noopener">Acceso administración Web y SSH OPNSense</a></li>
</ul>
<p>Saludos.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-opnsense-en-azure/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">17053</post-id>	</item>
		<item>
		<title>VPN site to site IPSEC entre Fortigate on-premise y Fortigate Azure</title>
		<link>https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure</link>
					<comments>https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 17 Jul 2023 07:16:51 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure Networking]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16450</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo configurar una VPN site to site IPSEC entre Fortigate on-premise y Fortigate Azure. La topología que vamos a utilizar será esta: Lo primero que vamos a realizar será acceder a&#8230; <a href="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo configurar una VPN site to site IPSEC entre Fortigate on-premise y Fortigate Azure.</p>
<p>La topología que vamos a utilizar será esta:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png?ssl=1" data-lbwps-width="1133" data-lbwps-height="730" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16451" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png?fit=1133%2C730&amp;ssl=1" data-orig-size="1133,730" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png?fit=640%2C413&amp;ssl=1" class="aligncenter size-full wp-image-16451" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png?resize=640%2C412&#038;ssl=1" alt="" width="640" height="412" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png?w=1133&amp;ssl=1 1133w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png?resize=595%2C383&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png?resize=960%2C619&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_1.png?resize=768%2C495&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo primero que vamos a realizar será acceder a nuestro Fortigate on-premise, y sobre <strong>VPN &gt; Túneles IPsec &gt; Crear nuevo &gt; IPsec Tunnel</strong>, empezaremos a crear el primer extremo de la VPN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png?ssl=1" data-lbwps-width="1300" data-lbwps-height="429" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16452" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png?fit=1300%2C429&amp;ssl=1" data-orig-size="1300,429" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png?fit=640%2C211&amp;ssl=1" class="aligncenter size-full wp-image-16452" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png?resize=640%2C211&#038;ssl=1" alt="" width="640" height="211" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png?w=1300&amp;ssl=1 1300w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png?resize=595%2C196&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png?resize=960%2C317&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_2.png?resize=768%2C253&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Configuración de VPN</strong> seleccionamos <strong>Personalizar</strong> y le indicamos un <strong>Nombre</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?ssl=1" data-lbwps-width="1348" data-lbwps-height="356" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16453" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?fit=1348%2C356&amp;ssl=1" data-orig-size="1348,356" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?fit=640%2C169&amp;ssl=1" class="aligncenter size-full wp-image-16453" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?resize=640%2C169&#038;ssl=1" alt="" width="640" height="169" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?w=1348&amp;ssl=1 1348w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?resize=595%2C157&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?resize=960%2C254&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?resize=768%2C203&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En la parte de <strong>Red</strong> configuramos la IP estática que tenemos asignada al Fortigate de Azure y la interface de salida:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_4.png?ssl=1" data-lbwps-width="958" data-lbwps-height="629" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16454" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_4.png?fit=958%2C629&amp;ssl=1" data-orig-size="958,629" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_4.png?fit=640%2C420&amp;ssl=1" class="aligncenter size-full wp-image-16454" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_4.png?resize=640%2C420&#038;ssl=1" alt="" width="640" height="420" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_4.png?w=958&amp;ssl=1 958w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_4.png?resize=595%2C391&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_4.png?resize=768%2C504&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Autenticación</strong> le indicamos la Key compartida:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png?ssl=1" data-lbwps-width="1009" data-lbwps-height="291" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16455" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png?fit=1009%2C291&amp;ssl=1" data-orig-size="1009,291" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png?fit=640%2C185&amp;ssl=1" class="aligncenter size-full wp-image-16455" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png?resize=640%2C185&#038;ssl=1" alt="" width="640" height="185" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png?w=1009&amp;ssl=1 1009w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png?resize=595%2C172&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png?resize=960%2C277&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_5.png?resize=768%2C221&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos la <strong>fase 1</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_6.png?ssl=1" data-lbwps-width="959" data-lbwps-height="480" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16456" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_6.png?fit=959%2C480&amp;ssl=1" data-orig-size="959,480" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_6.png?fit=640%2C320&amp;ssl=1" class="aligncenter size-full wp-image-16456" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_6.png?resize=640%2C320&#038;ssl=1" alt="" width="640" height="320" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_6.png?w=959&amp;ssl=1 959w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_6.png?resize=595%2C298&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_6.png?resize=768%2C384&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos la <strong>fase2</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png?ssl=1" data-lbwps-width="1256" data-lbwps-height="1008" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16457" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png?fit=1256%2C1008&amp;ssl=1" data-orig-size="1256,1008" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png?fit=640%2C513&amp;ssl=1" class="aligncenter size-full wp-image-16457" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png?resize=640%2C514&#038;ssl=1" alt="" width="640" height="514" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png?w=1256&amp;ssl=1 1256w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png?resize=595%2C478&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png?resize=960%2C770&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_7.png?resize=768%2C616&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver ya tenemos el primer extremo de la VPN configurado, el de la parte on-premise:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?ssl=1" data-lbwps-width="1653" data-lbwps-height="351" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8-1536x326.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16458" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?fit=1653%2C351&amp;ssl=1" data-orig-size="1653,351" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?fit=640%2C136&amp;ssl=1" class="aligncenter size-full wp-image-16458" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?resize=640%2C136&#038;ssl=1" alt="" width="640" height="136" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?w=1653&amp;ssl=1 1653w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?resize=595%2C126&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?resize=960%2C204&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?resize=768%2C163&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?resize=1536%2C326&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a crear las <strong>políticas</strong>:</li>
</ul>
<ul>
<li>Accedemos a <strong>Políticas y objetos&gt; Política IPv4 &gt; Crear nuevo</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_9.png?ssl=1" data-lbwps-width="952" data-lbwps-height="439" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16459" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_9.png?fit=952%2C439&amp;ssl=1" data-orig-size="952,439" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_9.png?fit=640%2C295&amp;ssl=1" class="aligncenter size-full wp-image-16459" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_9.png?resize=640%2C295&#038;ssl=1" alt="" width="640" height="295" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_9.png?w=952&amp;ssl=1 952w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_9.png?resize=595%2C274&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_9.png?resize=768%2C354&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Creamos una política para la conexión de sitio a sitio que permita el tráfico saliente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png?ssl=1" data-lbwps-width="1235" data-lbwps-height="1038" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16460" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png?fit=1235%2C1038&amp;ssl=1" data-orig-size="1235,1038" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png?fit=640%2C538&amp;ssl=1" class="aligncenter size-full wp-image-16460" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png?resize=640%2C538&#038;ssl=1" alt="" width="640" height="538" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png?w=1235&amp;ssl=1 1235w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png?resize=595%2C500&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png?resize=960%2C807&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_10.png?resize=768%2C645&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Creamos otra política para la conexión de sitio a sitio que permita el tráfico entrante:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png?ssl=1" data-lbwps-width="1248" data-lbwps-height="1040" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16461" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png?fit=1248%2C1040&amp;ssl=1" data-orig-size="1248,1040" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png?fit=640%2C533&amp;ssl=1" class="aligncenter size-full wp-image-16461" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png?resize=640%2C533&#038;ssl=1" alt="" width="640" height="533" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png?w=1248&amp;ssl=1 1248w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png?resize=595%2C496&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png?resize=960%2C800&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_11.png?resize=768%2C640&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí podemos ver las políticas creadas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?ssl=1" data-lbwps-width="1844" data-lbwps-height="558" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12-1536x465.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16462" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?fit=1844%2C558&amp;ssl=1" data-orig-size="1844,558" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?fit=640%2C193&amp;ssl=1" class="aligncenter size-full wp-image-16462" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?resize=640%2C194&#038;ssl=1" alt="" width="640" height="194" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?w=1844&amp;ssl=1 1844w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?resize=595%2C180&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?resize=960%2C290&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?resize=768%2C232&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?resize=1536%2C465&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_12.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora creamos la ruta estática hacia Azure:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png?ssl=1" data-lbwps-width="1273" data-lbwps-height="511" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16463" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png?fit=1273%2C511&amp;ssl=1" data-orig-size="1273,511" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png?fit=640%2C257&amp;ssl=1" class="aligncenter size-full wp-image-16463" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png?resize=640%2C257&#038;ssl=1" alt="" width="640" height="257" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png?w=1273&amp;ssl=1 1273w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png?resize=595%2C239&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png?resize=960%2C385&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_13.png?resize=768%2C308&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?ssl=1" data-lbwps-width="1775" data-lbwps-height="412" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14-1536x357.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16464" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?fit=1775%2C412&amp;ssl=1" data-orig-size="1775,412" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?fit=640%2C149&amp;ssl=1" class="aligncenter size-full wp-image-16464" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?resize=640%2C149&#038;ssl=1" alt="" width="640" height="149" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?w=1775&amp;ssl=1 1775w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?resize=595%2C138&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?resize=960%2C223&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?resize=768%2C178&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?resize=1536%2C357&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_14.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo segundo que vamos a realizar será acceder a nuestro Fortigate en Azure, y sobre <strong>VPN &gt; Túneles IPsec &gt; Crear nuevo &gt; IPsec Tunnel</strong>, empezaremos a crear el segundo extremo de la VPN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png?ssl=1" data-lbwps-width="1245" data-lbwps-height="298" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16465" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png?fit=1245%2C298&amp;ssl=1" data-orig-size="1245,298" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png?fit=640%2C153&amp;ssl=1" class="aligncenter size-full wp-image-16465" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png?resize=640%2C153&#038;ssl=1" alt="" width="640" height="153" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png?w=1245&amp;ssl=1 1245w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png?resize=595%2C142&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png?resize=960%2C230&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_15.png?resize=768%2C184&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Configuración de VPN</strong> seleccionamos <strong>Personalizar</strong> y le indicamos un <strong>Nombre</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?ssl=1" data-lbwps-width="1355" data-lbwps-height="311" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16466" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?fit=1355%2C311&amp;ssl=1" data-orig-size="1355,311" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?fit=640%2C147&amp;ssl=1" class="aligncenter size-full wp-image-16466" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?resize=640%2C147&#038;ssl=1" alt="" width="640" height="147" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?w=1355&amp;ssl=1 1355w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?resize=595%2C137&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?resize=960%2C220&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?resize=768%2C176&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_16.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En la parte de <strong>Red</strong> configuramos la IP estática que tenemos asignada al Fortigate on-premise y la interface de salida:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png?ssl=1" data-lbwps-width="993" data-lbwps-height="850" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16467" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png?fit=993%2C850&amp;ssl=1" data-orig-size="993,850" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png?fit=640%2C548&amp;ssl=1" class="aligncenter size-full wp-image-16467" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png?resize=640%2C548&#038;ssl=1" alt="" width="640" height="548" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png?w=993&amp;ssl=1 993w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png?resize=595%2C509&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png?resize=960%2C822&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_17.png?resize=768%2C657&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Autenticación</strong> le indicamos la Key compartida:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_18.png?ssl=1" data-lbwps-width="956" data-lbwps-height="289" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16468" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_18.png?fit=956%2C289&amp;ssl=1" data-orig-size="956,289" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_18.png?fit=640%2C193&amp;ssl=1" class="aligncenter size-full wp-image-16468" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_18.png?resize=640%2C193&#038;ssl=1" alt="" width="640" height="193" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_18.png?w=956&amp;ssl=1 956w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_18.png?resize=595%2C180&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_18.png?resize=768%2C232&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos la <strong>fase 1</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_19.png?ssl=1" data-lbwps-width="958" data-lbwps-height="596" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16469" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_19.png?fit=958%2C596&amp;ssl=1" data-orig-size="958,596" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_19.png?fit=640%2C398&amp;ssl=1" class="aligncenter size-full wp-image-16469" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_19.png?resize=640%2C398&#038;ssl=1" alt="" width="640" height="398" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_19.png?w=958&amp;ssl=1 958w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_19.png?resize=595%2C370&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_19.png?resize=768%2C478&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos la <strong>fase2</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png?ssl=1" data-lbwps-width="1088" data-lbwps-height="956" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16470" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png?fit=1088%2C956&amp;ssl=1" data-orig-size="1088,956" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png?fit=640%2C563&amp;ssl=1" class="aligncenter size-full wp-image-16470" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png?resize=640%2C562&#038;ssl=1" alt="" width="640" height="562" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png?w=1088&amp;ssl=1 1088w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png?resize=595%2C523&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png?resize=960%2C844&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_20.png?resize=768%2C675&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver ya tenemos el segundo extremo de la VPN configurado, el de la parte de Azure:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?ssl=1" data-lbwps-width="1675" data-lbwps-height="255" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21-1536x234.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16471" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?fit=1675%2C255&amp;ssl=1" data-orig-size="1675,255" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?fit=640%2C97&amp;ssl=1" class="aligncenter size-full wp-image-16471" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?resize=640%2C97&#038;ssl=1" alt="" width="640" height="97" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?w=1675&amp;ssl=1 1675w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?resize=595%2C91&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?resize=960%2C146&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?resize=768%2C117&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?resize=1536%2C234&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_21.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a crear las <strong>políticas</strong>:</li>
</ul>
<ul>
<li>Accedemos a <strong>Políticas y objetos&gt; Firewall Policy&gt; Crear nuevo</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?ssl=1" data-lbwps-width="1835" data-lbwps-height="260" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22-1536x218.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16472" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?fit=1835%2C260&amp;ssl=1" data-orig-size="1835,260" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?fit=640%2C91&amp;ssl=1" class="aligncenter size-full wp-image-16472" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?resize=640%2C91&#038;ssl=1" alt="" width="640" height="91" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?w=1835&amp;ssl=1 1835w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?resize=595%2C84&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?resize=960%2C136&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?resize=768%2C109&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?resize=1536%2C218&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_22.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Creamos una política para la conexión de sitio a sitio que permita el tráfico saliente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png?ssl=1" data-lbwps-width="1234" data-lbwps-height="1079" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16473" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png?fit=1234%2C1079&amp;ssl=1" data-orig-size="1234,1079" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png?fit=640%2C559&amp;ssl=1" class="aligncenter size-full wp-image-16473" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png?resize=640%2C560&#038;ssl=1" alt="" width="640" height="560" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png?w=1234&amp;ssl=1 1234w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png?resize=595%2C520&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png?resize=960%2C839&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_23.png?resize=768%2C672&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Creamos otra política para la conexión de sitio a sitio que permita el tráfico entrante:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png?ssl=1" data-lbwps-width="1225" data-lbwps-height="1079" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16474" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png?fit=1225%2C1079&amp;ssl=1" data-orig-size="1225,1079" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png?fit=640%2C564&amp;ssl=1" class="aligncenter size-full wp-image-16474" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png?resize=640%2C564&#038;ssl=1" alt="" width="640" height="564" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png?w=1225&amp;ssl=1 1225w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png?resize=595%2C524&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png?resize=960%2C846&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_24.png?resize=768%2C676&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí podemos ver las políticas creadas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?ssl=1" data-lbwps-width="1868" data-lbwps-height="316" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25-1536x260.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16475" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?fit=1868%2C316&amp;ssl=1" data-orig-size="1868,316" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?fit=640%2C108&amp;ssl=1" class="aligncenter size-full wp-image-16475" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?resize=640%2C108&#038;ssl=1" alt="" width="640" height="108" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?w=1868&amp;ssl=1 1868w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?resize=595%2C101&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?resize=960%2C162&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?resize=768%2C130&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?resize=1536%2C260&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_25.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora creamos la ruta estática hacia nuestro entorno on-premise:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png?ssl=1" data-lbwps-width="1246" data-lbwps-height="731" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16476" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_26#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png?fit=1246%2C731&amp;ssl=1" data-orig-size="1246,731" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_26" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png?fit=640%2C375&amp;ssl=1" class="aligncenter size-full wp-image-16476" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png?resize=640%2C375&#038;ssl=1" alt="" width="640" height="375" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png?w=1246&amp;ssl=1 1246w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png?resize=595%2C349&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png?resize=960%2C563&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_26.png?resize=768%2C451&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?ssl=1" data-lbwps-width="1801" data-lbwps-height="324" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27-1536x276.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16477" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_27#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?fit=1801%2C324&amp;ssl=1" data-orig-size="1801,324" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_27" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?fit=640%2C115&amp;ssl=1" class="aligncenter size-full wp-image-16477" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?resize=640%2C115&#038;ssl=1" alt="" width="640" height="115" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?w=1801&amp;ssl=1 1801w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?resize=595%2C107&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?resize=960%2C173&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?resize=768%2C138&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?resize=1536%2C276&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_27.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, ya tenemos el túnel IPSEC levantado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?ssl=1" data-lbwps-width="1661" data-lbwps-height="428" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28-1536x396.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16478" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_28#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?fit=1661%2C428&amp;ssl=1" data-orig-size="1661,428" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_28" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?fit=640%2C165&amp;ssl=1" class="aligncenter size-full wp-image-16478" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?resize=640%2C165&#038;ssl=1" alt="" width="640" height="165" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?w=1661&amp;ssl=1 1661w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?resize=595%2C153&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?resize=960%2C247&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?resize=768%2C198&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?resize=1536%2C396&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_28.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?ssl=1" data-lbwps-width="1657" data-lbwps-height="260" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29-1536x241.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16479" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_29#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?fit=1657%2C260&amp;ssl=1" data-orig-size="1657,260" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_29" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?fit=640%2C101&amp;ssl=1" class="aligncenter size-full wp-image-16479" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?resize=640%2C100&#038;ssl=1" alt="" width="640" height="100" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?w=1657&amp;ssl=1 1657w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?resize=595%2C93&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?resize=960%2C151&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?resize=768%2C121&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?resize=1536%2C241&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_29.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para verificar que todo funciona correctamente vamos a realizar un ping desde una máquina on-premise a una máquina en Azure y viceversa:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?ssl=1" data-lbwps-width="1697" data-lbwps-height="635" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30-1536x575.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16480" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_30#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?fit=1697%2C635&amp;ssl=1" data-orig-size="1697,635" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_30" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?fit=640%2C239&amp;ssl=1" class="aligncenter size-full wp-image-16480" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?resize=640%2C239&#038;ssl=1" alt="" width="640" height="239" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?w=1697&amp;ssl=1 1697w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?resize=595%2C223&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?resize=960%2C359&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?resize=768%2C287&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?resize=1536%2C575&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_30.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png?ssl=1" data-lbwps-width="997" data-lbwps-height="458" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16481" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_31#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png?fit=997%2C458&amp;ssl=1" data-orig-size="997,458" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_31" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png?fit=640%2C294&amp;ssl=1" class="aligncenter size-full wp-image-16481" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png?resize=640%2C294&#038;ssl=1" alt="" width="640" height="294" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png?w=997&amp;ssl=1 997w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png?resize=595%2C273&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png?resize=960%2C441&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_31.png?resize=768%2C353&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png?ssl=1" data-lbwps-width="1036" data-lbwps-height="754" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16482" data-permalink="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/vstsiefopyfa_32#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png?fit=1036%2C754&amp;ssl=1" data-orig-size="1036,754" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="vstsiefopyfa_32" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png?fit=640%2C466&amp;ssl=1" class="aligncenter size-full wp-image-16482" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png?resize=640%2C466&#038;ssl=1" alt="" width="640" height="466" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png?w=1036&amp;ssl=1 1036w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png?resize=595%2C433&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png?resize=960%2C699&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/vstsiefopyfa_32.png?resize=768%2C559&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure/feed</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16450</post-id>	</item>
		<item>
		<title>Desplegar y configurar tabla de rutas en Azure</title>
		<link>https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure</link>
					<comments>https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 10 Jul 2023 09:54:10 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure Networking]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16428</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo desplegar y configurar una tabla de rutas en Azure. La topología que vamos a utilizar será esta: Accedemos al Marketplace, buscamos Route table y damos a crear: Sobre Básico le&#8230; <a href="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo desplegar y configurar una tabla de rutas en Azure.</p>
<p>La topología que vamos a utilizar será esta:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png?ssl=1" data-lbwps-width="1133" data-lbwps-height="730" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16429" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png?fit=1133%2C730&amp;ssl=1" data-orig-size="1133,730" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png?fit=640%2C413&amp;ssl=1" class="aligncenter size-full wp-image-16429" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png?resize=640%2C412&#038;ssl=1" alt="" width="640" height="412" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png?w=1133&amp;ssl=1 1133w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png?resize=595%2C383&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png?resize=960%2C619&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_1.png?resize=768%2C495&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Accedemos al Marketplace, buscamos Route table y damos a crear:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_2.png?ssl=1" data-lbwps-width="672" data-lbwps-height="624" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16430" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_2.png?fit=672%2C624&amp;ssl=1" data-orig-size="672,624" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_2.png?fit=640%2C594&amp;ssl=1" class="aligncenter size-full wp-image-16430" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_2.png?resize=640%2C594&#038;ssl=1" alt="" width="640" height="594" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_2.png?w=672&amp;ssl=1 672w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_2.png?resize=595%2C553&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Básico</strong> le indicamos el grupo de recursos, la región, le damos un nombre y le indicamos que propague las rutas de puerta de enlace:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png?ssl=1" data-lbwps-width="1077" data-lbwps-height="906" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16431" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png?fit=1077%2C906&amp;ssl=1" data-orig-size="1077,906" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png?fit=640%2C539&amp;ssl=1" class="aligncenter size-full wp-image-16431" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png?resize=640%2C538&#038;ssl=1" alt="" width="640" height="538" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png?w=1077&amp;ssl=1 1077w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png?resize=595%2C501&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png?resize=960%2C808&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_3.png?resize=768%2C646&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Etiquetas</strong> podemos configurar las que nos interesen:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png?ssl=1" data-lbwps-width="1009" data-lbwps-height="911" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16432" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png?fit=1009%2C911&amp;ssl=1" data-orig-size="1009,911" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png?fit=640%2C578&amp;ssl=1" class="aligncenter size-full wp-image-16432" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png?resize=640%2C578&#038;ssl=1" alt="" width="640" height="578" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png?w=1009&amp;ssl=1 1009w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png?resize=595%2C537&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png?resize=960%2C867&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_4.png?resize=768%2C693&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Revisar y crear</strong> nos muestra un resumen sobre todo lo que le hemos configurado a la tabla de rutas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png?ssl=1" data-lbwps-width="986" data-lbwps-height="908" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16433" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png?fit=986%2C908&amp;ssl=1" data-orig-size="986,908" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png?fit=640%2C589&amp;ssl=1" class="aligncenter size-full wp-image-16433" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png?resize=640%2C589&#038;ssl=1" alt="" width="640" height="589" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png?w=986&amp;ssl=1 986w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png?resize=595%2C548&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png?resize=960%2C884&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_5.png?resize=768%2C707&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, comienza a implementar la tabla de rutas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?ssl=1" data-lbwps-width="1575" data-lbwps-height="462" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6-1536x451.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16434" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?fit=1575%2C462&amp;ssl=1" data-orig-size="1575,462" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?fit=640%2C188&amp;ssl=1" class="aligncenter size-full wp-image-16434" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?resize=640%2C188&#038;ssl=1" alt="" width="640" height="188" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?w=1575&amp;ssl=1 1575w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?resize=595%2C175&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?resize=960%2C282&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?resize=768%2C225&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?resize=1536%2C451&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_6.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos que se ha implementado correctamente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?ssl=1" data-lbwps-width="1591" data-lbwps-height="527" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7-1536x509.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16435" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?fit=1591%2C527&amp;ssl=1" data-orig-size="1591,527" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?fit=640%2C212&amp;ssl=1" class="aligncenter size-full wp-image-16435" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?resize=640%2C212&#038;ssl=1" alt="" width="640" height="212" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?w=1591&amp;ssl=1 1591w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?resize=595%2C197&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?resize=960%2C318&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?resize=768%2C254&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?resize=1536%2C509&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_7.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Accedemos al recurso y sobre subredes vamos a asociar la subred LAN que configuramos anteriormente, esta subred es dónde vamos a ubicar las máquinas virtuales de nuestra infraestructura en Azure:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?ssl=1" data-lbwps-width="1734" data-lbwps-height="509" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8-1536x451.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16436" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?fit=1734%2C509&amp;ssl=1" data-orig-size="1734,509" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?fit=640%2C188&amp;ssl=1" class="aligncenter size-full wp-image-16436" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?resize=640%2C188&#038;ssl=1" alt="" width="640" height="188" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?w=1734&amp;ssl=1 1734w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?resize=595%2C175&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?resize=960%2C282&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?resize=768%2C225&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?resize=1536%2C451&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<ul>
<li>Como podemos ver, ya la tenemos asociada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?ssl=1" data-lbwps-width="1734" data-lbwps-height="503" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10-1536x446.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16438" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?fit=1734%2C503&amp;ssl=1" data-orig-size="1734,503" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?fit=640%2C185&amp;ssl=1" class="aligncenter size-full wp-image-16438" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?resize=640%2C186&#038;ssl=1" alt="" width="640" height="186" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?w=1734&amp;ssl=1 1734w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?resize=595%2C173&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?resize=960%2C278&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?resize=768%2C223&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?resize=1536%2C446&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a configurar las rutas, para ello, accedemos a Rutas a Agregar:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?ssl=1" data-lbwps-width="1765" data-lbwps-height="445" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11-1536x387.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16439" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?fit=1765%2C445&amp;ssl=1" data-orig-size="1765,445" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?fit=640%2C161&amp;ssl=1" class="aligncenter size-full wp-image-16439" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?resize=640%2C161&#038;ssl=1" alt="" width="640" height="161" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?w=1765&amp;ssl=1 1765w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?resize=595%2C150&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?resize=960%2C242&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?resize=768%2C194&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?resize=1536%2C387&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_11.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>La primera ruta que vamos a agregar, será la ruta por defecto:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?ssl=1" data-lbwps-width="1901" data-lbwps-height="910" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12-1536x735.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16440" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?fit=1901%2C910&amp;ssl=1" data-orig-size="1901,910" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?fit=640%2C307&amp;ssl=1" class="aligncenter size-full wp-image-16440" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?resize=640%2C306&#038;ssl=1" alt="" width="640" height="306" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?w=1901&amp;ssl=1 1901w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?resize=595%2C285&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?resize=960%2C460&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?resize=768%2C368&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?resize=1536%2C735&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_12.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>La siguiente ruta será para el acceso a la subred dónde vamos a ubicar nuestras máquinas virtuales:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?ssl=1" data-lbwps-width="1908" data-lbwps-height="910" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13-1536x733.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16441" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?fit=1908%2C910&amp;ssl=1" data-orig-size="1908,910" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?fit=640%2C305&amp;ssl=1" class="aligncenter size-full wp-image-16441" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?resize=640%2C305&#038;ssl=1" alt="" width="640" height="305" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?w=1908&amp;ssl=1 1908w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?resize=595%2C284&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?resize=960%2C458&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?resize=768%2C366&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?resize=1536%2C733&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_13.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos las rutas agregadas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="449" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14-1536x360.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16442" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?fit=1914%2C449&amp;ssl=1" data-orig-size="1914,449" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?fit=640%2C150&amp;ssl=1" class="aligncenter size-full wp-image-16442" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?resize=640%2C150&#038;ssl=1" alt="" width="640" height="150" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?resize=595%2C140&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?resize=960%2C225&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?resize=768%2C180&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?resize=1536%2C360&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_14.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Una vez configurada la tabla de rutas, accedemos a nuestro Fortigate en Azure, y nos vamos a crear estas tres rutas estáticas, la primera es la ruta por defecto, para que todo lo que no se encuentre en la tabla de enrutamiento del Forti lo envíe por la interface WAN al gateway de la subred external, la segunda ruta es para que todo lo configurado en el espacio de direcciones de la red virtual lo envíe por la interface LAN al gateway de la subred internal, y la tercera ruta son para servicios internos de Azure para que lo envíe por la interface LAN al gateway de la subred internal:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="350" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15-1536x281.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16443" data-permalink="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/dyctdrea_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?fit=1915%2C350&amp;ssl=1" data-orig-size="1915,350" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dyctdrea_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?fit=640%2C117&amp;ssl=1" class="aligncenter size-full wp-image-16443" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?resize=640%2C117&#038;ssl=1" alt="" width="640" height="117" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?resize=595%2C109&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?resize=960%2C175&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?resize=768%2C140&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?resize=1536%2C281&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dyctdrea_15.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16428</post-id>	</item>
		<item>
		<title>Despliegue Firewall Fortigate en Azure desde Marketplace</title>
		<link>https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace</link>
					<comments>https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 03 Jul 2023 07:31:02 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure Networking]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16405</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo desplegar un firewall Fortigate en Azure a través del Marketplace. La topología que vamos a utilizar será esta: Accedemos al Marketplace, buscamos por fortigate y seleccionamos la opción Fortinet FortiGate&#8230; <a href="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo desplegar un firewall Fortigate en Azure a través del Marketplace.</p>
<p>La topología que vamos a utilizar será esta:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png?ssl=1" data-lbwps-width="1133" data-lbwps-height="730" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16406" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png?fit=1133%2C730&amp;ssl=1" data-orig-size="1133,730" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png?fit=640%2C413&amp;ssl=1" class="aligncenter size-full wp-image-16406" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png?resize=640%2C412&#038;ssl=1" alt="" width="640" height="412" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png?w=1133&amp;ssl=1 1133w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png?resize=595%2C383&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png?resize=960%2C619&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_1.png?resize=768%2C495&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Accedemos al Marketplace, buscamos por fortigate y seleccionamos la opción <strong>Fortinet FortiGate Next-Generation Firewall &gt; Crear &gt; Single VM</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png?ssl=1" data-lbwps-width="1320" data-lbwps-height="735" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16407" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png?fit=1320%2C735&amp;ssl=1" data-orig-size="1320,735" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png?fit=640%2C357&amp;ssl=1" class="aligncenter size-full wp-image-16407" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png?resize=640%2C356&#038;ssl=1" alt="" width="640" height="356" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png?w=1320&amp;ssl=1 1320w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png?resize=595%2C331&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png?resize=960%2C535&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_2.png?resize=768%2C428&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En el despliegue del firewall sobre <strong>Básico</strong> le indicamos el grupo de recursos, la región, las credenciales de usuario, el prefijo del nombre, tipo de licencia y la versión de la imagen del Fortigate:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png?ssl=1" data-lbwps-width="1047" data-lbwps-height="908" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16408" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png?fit=1047%2C908&amp;ssl=1" data-orig-size="1047,908" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png?fit=640%2C555&amp;ssl=1" class="aligncenter size-full wp-image-16408" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png?resize=640%2C555&#038;ssl=1" alt="" width="640" height="555" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png?w=1047&amp;ssl=1 1047w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png?resize=595%2C516&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png?resize=960%2C833&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_3.png?resize=768%2C666&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Instance</strong> le indicamos el tamaño de máquina, le adjuntamos la licencia y le indicamos el nombre:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?ssl=1" data-lbwps-width="1017" data-lbwps-height="1040" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16409" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?fit=1017%2C1040&amp;ssl=1" data-orig-size="1017,1040" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?fit=640%2C655&amp;ssl=1" class="aligncenter size-full wp-image-16409" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?resize=640%2C654&#038;ssl=1" alt="" width="640" height="654" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?w=1017&amp;ssl=1 1017w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?resize=595%2C608&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?resize=960%2C982&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?resize=768%2C785&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_4.png?resize=50%2C50&amp;ssl=1 50w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Networking</strong> le indicamos la red virtual que vamos a utilizar y las subredes del firewall que ya configuramos en un post anterior:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?ssl=1" data-lbwps-width="1015" data-lbwps-height="1042" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16410" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?fit=1015%2C1042&amp;ssl=1" data-orig-size="1015,1042" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?fit=640%2C657&amp;ssl=1" class="aligncenter size-full wp-image-16410" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?resize=640%2C657&#038;ssl=1" alt="" width="640" height="657" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?w=1015&amp;ssl=1 1015w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?resize=595%2C611&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?resize=960%2C986&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?resize=768%2C788&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_5.png?resize=50%2C50&amp;ssl=1 50w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Public IP</strong> configuramos una IP pública básica y estática:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?ssl=1" data-lbwps-width="1903" data-lbwps-height="908" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6-1536x733.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16411" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?fit=1903%2C908&amp;ssl=1" data-orig-size="1903,908" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?fit=640%2C305&amp;ssl=1" class="aligncenter size-full wp-image-16411" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?resize=640%2C305&#038;ssl=1" alt="" width="640" height="305" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?w=1903&amp;ssl=1 1903w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?resize=595%2C284&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?resize=960%2C458&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?resize=768%2C366&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?resize=1536%2C733&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_6.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre<strong> Advanced</strong> no tocamos nada ya que no tenemos configurado FortiManager:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?ssl=1" data-lbwps-width="1060" data-lbwps-height="1038" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16412" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?fit=1060%2C1038&amp;ssl=1" data-orig-size="1060,1038" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?fit=640%2C627&amp;ssl=1" class="aligncenter size-full wp-image-16412" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?resize=640%2C627&#038;ssl=1" alt="" width="640" height="627" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?w=1060&amp;ssl=1 1060w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?resize=595%2C583&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?resize=960%2C940&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?resize=768%2C752&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_7.png?resize=50%2C50&amp;ssl=1 50w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Nos muestra un resumen de todas las configuraciones realizadas, comenzamos a crear la máquina:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png?ssl=1" data-lbwps-width="917" data-lbwps-height="902" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16413" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png?fit=917%2C902&amp;ssl=1" data-orig-size="917,902" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png?fit=640%2C630&amp;ssl=1" class="aligncenter size-full wp-image-16413" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png?resize=640%2C630&#038;ssl=1" alt="" width="640" height="630" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png?w=917&amp;ssl=1 917w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png?resize=595%2C585&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png?resize=768%2C755&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_8.png?resize=50%2C50&amp;ssl=1 50w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, comienza el despliegue:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?ssl=1" data-lbwps-width="1595" data-lbwps-height="558" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9-1536x537.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16414" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?fit=1595%2C558&amp;ssl=1" data-orig-size="1595,558" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?fit=640%2C224&amp;ssl=1" class="aligncenter size-full wp-image-16414" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?resize=640%2C224&#038;ssl=1" alt="" width="640" height="224" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?w=1595&amp;ssl=1 1595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?resize=595%2C208&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?resize=960%2C336&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?resize=768%2C269&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?resize=1536%2C537&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_9.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos que ya ha terminado y se ha implementado correctamente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?ssl=1" data-lbwps-width="1604" data-lbwps-height="803" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10-1536x769.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16415" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?fit=1604%2C803&amp;ssl=1" data-orig-size="1604,803" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?fit=640%2C321&amp;ssl=1" class="aligncenter size-full wp-image-16415" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?resize=640%2C320&#038;ssl=1" alt="" width="640" height="320" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?w=1604&amp;ssl=1 1604w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?resize=595%2C298&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?resize=960%2C481&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?resize=768%2C384&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?resize=1536%2C769&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora accedemos al grupo de recursos y clicamos sobre la máquina virtual:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?ssl=1" data-lbwps-width="1756" data-lbwps-height="795" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11-1536x695.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16416" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?fit=1756%2C795&amp;ssl=1" data-orig-size="1756,795" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?fit=640%2C290&amp;ssl=1" class="aligncenter size-full wp-image-16416" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?resize=640%2C290&#038;ssl=1" alt="" width="640" height="290" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?w=1756&amp;ssl=1 1756w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?resize=595%2C269&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?resize=960%2C435&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?resize=768%2C348&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?resize=1536%2C695&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?resize=300%2C135&amp;ssl=1 300w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_11.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En la máquina virtual accedemos a Redes y cómo podemos ver tenemos dos interfaces de red, una es la interface WAN del Fortigate que tiene una IP privada y otra pública, y la otra es la interface LAN que solo tiene una IP privada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="603" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12-1536x484.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16417" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?fit=1913%2C603&amp;ssl=1" data-orig-size="1913,603" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?fit=640%2C202&amp;ssl=1" class="aligncenter size-full wp-image-16417" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?resize=640%2C202&#038;ssl=1" alt="" width="640" height="202" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?resize=595%2C188&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?resize=960%2C303&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?resize=768%2C242&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?resize=1536%2C484&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_12.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="609" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13-1536x488.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16418" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?fit=1915%2C609&amp;ssl=1" data-orig-size="1915,609" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?fit=640%2C203&amp;ssl=1" class="aligncenter size-full wp-image-16418" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?resize=640%2C204&#038;ssl=1" alt="" width="640" height="204" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?resize=595%2C189&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?resize=960%2C305&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?resize=768%2C244&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?resize=1536%2C488&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_13.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para acceder al firewall accedemos a través de su IP pública:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png?ssl=1" data-lbwps-width="1309" data-lbwps-height="762" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16419" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png?fit=1309%2C762&amp;ssl=1" data-orig-size="1309,762" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png?fit=640%2C373&amp;ssl=1" class="aligncenter size-full wp-image-16419" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png?resize=640%2C373&#038;ssl=1" alt="" width="640" height="373" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png?w=1309&amp;ssl=1 1309w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png?resize=595%2C346&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png?resize=960%2C559&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_14.png?resize=768%2C447&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?ssl=1" data-lbwps-width="1911" data-lbwps-height="801" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15-1536x644.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16420" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?fit=1911%2C801&amp;ssl=1" data-orig-size="1911,801" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?fit=640%2C268&amp;ssl=1" class="aligncenter size-full wp-image-16420" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?resize=640%2C268&#038;ssl=1" alt="" width="640" height="268" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?w=1911&amp;ssl=1 1911w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?resize=595%2C249&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?resize=960%2C402&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?resize=768%2C322&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?resize=1536%2C644&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_15.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Le aplicamos un alias a sus interfaces como WAN y LAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="617" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16-1536x495.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16421" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?fit=1914%2C617&amp;ssl=1" data-orig-size="1914,617" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?fit=640%2C206&amp;ssl=1" class="aligncenter size-full wp-image-16421" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?resize=640%2C206&#038;ssl=1" alt="" width="640" height="206" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?resize=595%2C192&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?resize=960%2C309&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?resize=768%2C248&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?resize=1536%2C495&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_16.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png?ssl=1" data-lbwps-width="1231" data-lbwps-height="946" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16422" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png?fit=1231%2C946&amp;ssl=1" data-orig-size="1231,946" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png?fit=640%2C492&amp;ssl=1" class="aligncenter size-full wp-image-16422" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png?resize=640%2C492&#038;ssl=1" alt="" width="640" height="492" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png?w=1231&amp;ssl=1 1231w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png?resize=595%2C457&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png?resize=960%2C738&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_17.png?resize=768%2C590&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png?ssl=1" data-lbwps-width="1229" data-lbwps-height="954" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16423" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png?fit=1229%2C954&amp;ssl=1" data-orig-size="1229,954" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png?fit=640%2C497&amp;ssl=1" class="aligncenter size-full wp-image-16423" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png?resize=640%2C497&#038;ssl=1" alt="" width="640" height="497" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png?w=1229&amp;ssl=1 1229w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png?resize=595%2C462&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png?resize=960%2C745&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_18.png?resize=768%2C596&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Y así nos quedaría:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?ssl=1" data-lbwps-width="1432" data-lbwps-height="601" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16424" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?fit=1432%2C601&amp;ssl=1" data-orig-size="1432,601" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?fit=640%2C269&amp;ssl=1" class="aligncenter size-full wp-image-16424" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?resize=640%2C269&#038;ssl=1" alt="" width="640" height="269" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?w=1432&amp;ssl=1 1432w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?resize=595%2C250&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?resize=960%2C403&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?resize=768%2C322&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_19.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>También configuramos el acceso a nuestro Fortigate para que lo haga a través del puerto 30443:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png?ssl=1" data-lbwps-width="1221" data-lbwps-height="951" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16425" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png?fit=1221%2C951&amp;ssl=1" data-orig-size="1221,951" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png?fit=640%2C499&amp;ssl=1" class="aligncenter size-full wp-image-16425" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png?resize=640%2C498&#038;ssl=1" alt="" width="640" height="498" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png?w=1221&amp;ssl=1 1221w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png?resize=595%2C463&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png?resize=960%2C748&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_20.png?resize=768%2C598&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, ahora tenemos que acceder a través del puerto configurado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png?ssl=1" data-lbwps-width="1183" data-lbwps-height="706" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16426" data-permalink="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/dffeadm_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png?fit=1183%2C706&amp;ssl=1" data-orig-size="1183,706" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dffeadm_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png?fit=640%2C382&amp;ssl=1" class="aligncenter size-full wp-image-16426" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png?resize=640%2C382&#038;ssl=1" alt="" width="640" height="382" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png?w=1183&amp;ssl=1 1183w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png?resize=595%2C355&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png?resize=960%2C573&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dffeadm_21.png?resize=768%2C458&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16405</post-id>	</item>
		<item>
		<title>Despliegue y configuración red virtual en Azure para Firewall Fortigate</title>
		<link>https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate</link>
					<comments>https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Fri, 30 Jun 2023 09:07:29 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure Networking]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16393</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo desplegar y configurar una red virtual en Azure para firewall Fortigate. La topología que vamos a utilizar será esta: Empezaremos con el despliegue y la configuración de la red virtual&#8230; <a href="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo desplegar y configurar una red virtual en Azure para firewall Fortigate.</p>
<p>La topología que vamos a utilizar será esta:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png?ssl=1" data-lbwps-width="1133" data-lbwps-height="730" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16394" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png?fit=1133%2C730&amp;ssl=1" data-orig-size="1133,730" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png?fit=640%2C413&amp;ssl=1" class="aligncenter size-full wp-image-16394" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png?resize=640%2C412&#038;ssl=1" alt="" width="640" height="412" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png?w=1133&amp;ssl=1 1133w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png?resize=595%2C383&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png?resize=960%2C619&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_1.png?resize=768%2C495&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Empezaremos con el despliegue y la configuración de la red virtual en Azure, para ello, vamos a seleccionar un espacio de direcciones en la red virtual, y le configuraremos las distintas subredes que va a utilizar el firewall y la que utilizaremos como la red local de Azure dónde se conectarán nuestras máquinas virtuales:</li>
<li>Red virtual: <strong>rgs-firewall-vnet </strong>192.168.128.0/18</li>
<li>Subred Externa: <strong>ExternalSubnetFortigate </strong>192.168.191.0/27</li>
<li>Subred Interna: <strong>InternalSub</strong><strong>netFortigate </strong>192.168.191.32/27</li>
<li>Subred Protected: <strong>Protected</strong><strong>SubnetFortigate </strong>192.168.191.64/27</li>
<li>LAN Azure: <strong>Subvnet_rgs_192.</strong><strong>168.130.0-24_</strong><strong>LAN </strong>192.168.130.0/24</li>
</ul>
<ul>
<li>Todos los recursos creados los vamos a ubicar dentro de este grupo de recursos:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?ssl=1" data-lbwps-width="1902" data-lbwps-height="809" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2-1536x653.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16395" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?fit=1902%2C809&amp;ssl=1" data-orig-size="1902,809" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?fit=640%2C272&amp;ssl=1" class="aligncenter size-full wp-image-16395" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?resize=640%2C272&#038;ssl=1" alt="" width="640" height="272" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?w=1902&amp;ssl=1 1902w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?resize=595%2C253&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?resize=960%2C408&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?resize=768%2C327&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?resize=1536%2C653&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_2.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Nos creamos la red virtual, dónde en <strong>Datos básicos</strong> le indicamos, el grupo de recursos y el nombre:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png?ssl=1" data-lbwps-width="1044" data-lbwps-height="909" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16396" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png?fit=1044%2C909&amp;ssl=1" data-orig-size="1044,909" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png?fit=640%2C557&amp;ssl=1" class="aligncenter size-full wp-image-16396" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png?resize=640%2C557&#038;ssl=1" alt="" width="640" height="557" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png?w=1044&amp;ssl=1 1044w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png?resize=595%2C518&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png?resize=960%2C836&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_3.png?resize=768%2C669&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Seguridad </strong>lo dejamos por defecto:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png?ssl=1" data-lbwps-width="1011" data-lbwps-height="909" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16397" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png?fit=1011%2C909&amp;ssl=1" data-orig-size="1011,909" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png?fit=640%2C575&amp;ssl=1" class="aligncenter size-full wp-image-16397" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png?resize=640%2C575&#038;ssl=1" alt="" width="640" height="575" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png?w=1011&amp;ssl=1 1011w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png?resize=595%2C535&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png?resize=960%2C863&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_4.png?resize=768%2C691&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Direcciones IP</strong> configuramos el espacio de direcciones y las subredes que vamos a utilizar:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png?ssl=1" data-lbwps-width="1046" data-lbwps-height="911" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16398" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png?fit=1046%2C911&amp;ssl=1" data-orig-size="1046,911" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png?fit=640%2C557&amp;ssl=1" class="aligncenter size-full wp-image-16398" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png?resize=640%2C557&#038;ssl=1" alt="" width="640" height="557" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png?w=1046&amp;ssl=1 1046w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png?resize=595%2C518&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png?resize=960%2C836&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_5.png?resize=768%2C669&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Etiquetas</strong> podemos configurar las que nos interesen:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png?ssl=1" data-lbwps-width="993" data-lbwps-height="908" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16399" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png?fit=993%2C908&amp;ssl=1" data-orig-size="993,908" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png?fit=640%2C585&amp;ssl=1" class="aligncenter size-full wp-image-16399" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png?resize=640%2C585&#038;ssl=1" alt="" width="640" height="585" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png?w=993&amp;ssl=1 993w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png?resize=595%2C544&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png?resize=960%2C878&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_6.png?resize=768%2C702&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Revisar y crear</strong> nos muestra un resumen sobre todo lo que le hemos configurado a la red virtual:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png?ssl=1" data-lbwps-width="1108" data-lbwps-height="1011" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16400" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png?fit=1108%2C1011&amp;ssl=1" data-orig-size="1108,1011" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png?fit=640%2C584&amp;ssl=1" class="aligncenter size-full wp-image-16400" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png?resize=640%2C584&#038;ssl=1" alt="" width="640" height="584" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png?w=1108&amp;ssl=1 1108w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png?resize=595%2C543&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png?resize=960%2C876&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_7.png?resize=768%2C701&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, el recurso de red virtual se ha creado correctamente, podemos ir al recurso:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?ssl=1" data-lbwps-width="1588" data-lbwps-height="607" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8-1536x587.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16401" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?fit=1588%2C607&amp;ssl=1" data-orig-size="1588,607" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?fit=640%2C245&amp;ssl=1" class="aligncenter size-full wp-image-16401" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?resize=640%2C245&#038;ssl=1" alt="" width="640" height="245" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?w=1588&amp;ssl=1 1588w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?resize=595%2C227&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?resize=960%2C367&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?resize=768%2C294&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?resize=1536%2C587&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Dónde podemos ver el <strong>Espacio de direcciones</strong> configurado y las <strong>Subredes</strong> que vamos a utilizar para desplegar el firewall Fortigate y para ubicar nuestras máquinas virtuales:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?ssl=1" data-lbwps-width="1588" data-lbwps-height="442" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9-1536x428.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16402" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?fit=1588%2C442&amp;ssl=1" data-orig-size="1588,442" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?fit=640%2C178&amp;ssl=1" class="aligncenter size-full wp-image-16402" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?resize=640%2C178&#038;ssl=1" alt="" width="640" height="178" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?w=1588&amp;ssl=1 1588w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?resize=595%2C166&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?resize=960%2C267&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?resize=768%2C214&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?resize=1536%2C428&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_9.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?ssl=1" data-lbwps-width="1812" data-lbwps-height="479" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10-1536x406.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16403" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/dycrveapff_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?fit=1812%2C479&amp;ssl=1" data-orig-size="1812,479" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycrveapff_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?fit=640%2C169&amp;ssl=1" class="aligncenter size-full wp-image-16403" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?resize=640%2C169&#038;ssl=1" alt="" width="640" height="169" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?w=1812&amp;ssl=1 1812w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?resize=595%2C157&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?resize=960%2C254&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?resize=768%2C203&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?resize=1536%2C406&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycrveapff_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate/feed</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16393</post-id>	</item>
		<item>
		<title>Despliegue y configuración de Firewall Fortigate en Azure</title>
		<link>https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-fortigate-en-azure</link>
					<comments>https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-fortigate-en-azure#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Tue, 27 Jun 2023 16:37:12 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Azure Networking]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16389</guid>

					<description><![CDATA[Hola a tod@s, En estos posts vamos a ver cómo desplegar y configurar un firewall Fortigate en Azure. La topología que vamos a utilizar será esta: Este post lo vamos a dividir en: Despliegue y configuración red virtual en Azure&#8230; <a href="https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-fortigate-en-azure" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En estos posts vamos a ver cómo desplegar y configurar un firewall Fortigate en Azure.</p>
<p>La topología que vamos a utilizar será esta:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png?ssl=1" data-lbwps-width="1133" data-lbwps-height="730" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16390" data-permalink="https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-fortigate-en-azure/dycffeaintro#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png?fit=1133%2C730&amp;ssl=1" data-orig-size="1133,730" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="dycffeaintro" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png?fit=640%2C413&amp;ssl=1" class="aligncenter size-full wp-image-16390" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png?resize=640%2C412&#038;ssl=1" alt="" width="640" height="412" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png?w=1133&amp;ssl=1 1133w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png?resize=595%2C383&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png?resize=960%2C619&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/06/dycffeaintro.png?resize=768%2C495&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>Este post lo vamos a dividir en:</p>
<ul>
<li><a href="https://blog.ragasys.es/despliegue-y-configuracion-red-virtual-en-azure-para-firewall-fortigate" target="_blank" rel="noopener">Despliegue y configuración red virtual en Azure para Firewall Fortigate</a></li>
<li><a href="https://blog.ragasys.es/despliegue-firewall-fortigate-en-azure-desde-marketplace" target="_blank" rel="noopener">Despliegue Firewall Fortigate en Azure desde Marketplace</a></li>
<li><a href="https://blog.ragasys.es/desplegar-y-configurar-tabla-de-rutas-en-azure" target="_blank" rel="noopener">Desplegar y configurar tabla de rutas en Azure</a></li>
<li><a href="https://blog.ragasys.es/vpn-site-to-site-ipsec-entre-fortigate-on-premise-y-fortigate-azure" target="_blank" rel="noopener">VPN site to site IPSEC entre Fortigate on-premise y Fortigate Azure</a></li>
</ul>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/despliegue-y-configuracion-de-firewall-fortigate-en-azure/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16389</post-id>	</item>
		<item>
		<title>AZURE – Creación de la conexión VPN Site to Site en Azure</title>
		<link>https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure</link>
					<comments>https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 27 Sep 2021 07:31:39 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=13801</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver cómo crear la conexión VPN Site to Site en Azure entre la puerta de enlace de la red virtual y el dispositivo VPN local. Accedemos a Conexiones &#62; Crear: En Datos&#8230; <a href="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver cómo crear la conexión VPN Site to Site en Azure entre la puerta de enlace de la red virtual y el dispositivo VPN local.</p>
<ul>
<li>Accedemos a <strong>Conexiones &gt; Crear</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?ssl=1" data-lbwps-width="1379" data-lbwps-height="691" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13802" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?fit=1379%2C691&amp;ssl=1" data-orig-size="1379,691" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?fit=640%2C321&amp;ssl=1" class="aligncenter size-full wp-image-13802" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?resize=640%2C321&#038;ssl=1" alt="" width="640" height="321" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?w=1379&amp;ssl=1 1379w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?resize=595%2C298&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?resize=960%2C481&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?resize=768%2C385&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_1.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En Datos básicos, configuramos:
<ul>
<li><strong>Nombre</strong>: asignamos un nombre a la conexión.</li>
<li><strong>Tipo de conexión</strong>: Seleccionamos <strong>Sitio a sitio (IPSec)</strong>.</li>
</ul>
</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?ssl=1" data-lbwps-width="1336" data-lbwps-height="894" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13803" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?fit=1336%2C894&amp;ssl=1" data-orig-size="1336,894" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?fit=640%2C428&amp;ssl=1" class="aligncenter size-full wp-image-13803" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?resize=640%2C428&#038;ssl=1" alt="" width="640" height="428" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?w=1336&amp;ssl=1 1336w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?resize=595%2C398&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?resize=960%2C642&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?resize=768%2C514&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_2.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Opciones</strong>, configuramos:</li>
</ul>
<ul>
<li style="list-style-type: none;">
<ul>
<li><strong>Puerta de enlace de red virtual</strong>, el valor es fijo porque se conecta desde esta puerta de enlace.</li>
<li><strong>Puerta de enlace de red local</strong>, seleccionamos elegir una puerta de enlace de red local y seleccionamos la puerta de enlace de red local que queremos utilizar.</li>
<li><strong>Clave compartida</strong> <strong>(PSK)</strong>, este valor debe ser el mismo que el que usa para el dispositivo VPN local.</li>
<li>Seleccionamos <strong>IKEv2</strong>.</li>
<li>Dejamos la casilla <strong>Usar la dirección IP privada de Azure</strong> desactivada.</li>
<li>Dejamos la casilla <strong>Habilitar BGP</strong> desactivada.</li>
</ul>
</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?ssl=1" data-lbwps-width="1360" data-lbwps-height="885" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13804" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?fit=1360%2C885&amp;ssl=1" data-orig-size="1360,885" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?fit=640%2C417&amp;ssl=1" class="aligncenter size-full wp-image-13804" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?resize=640%2C416&#038;ssl=1" alt="" width="640" height="416" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?w=1360&amp;ssl=1 1360w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?resize=595%2C387&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?resize=960%2C625&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?resize=768%2C500&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>Etiquetas </strong>las podemos configurar ahora o a posteriori, en mi caso, no vamos a configurar ninguna en este momento, ya dedicaremos un post a las Etiquetas, que como veremos pueden ser muy útiles, clic en <strong>Siguiente</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png?ssl=1" data-lbwps-width="1325" data-lbwps-height="877" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13805" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png?fit=1325%2C877&amp;ssl=1" data-orig-size="1325,877" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png?fit=640%2C423&amp;ssl=1" class="aligncenter size-full wp-image-13805" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png?resize=640%2C424&#038;ssl=1" alt="" width="640" height="424" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png?w=1325&amp;ssl=1 1325w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png?resize=595%2C394&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png?resize=960%2C635&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_4.png?resize=768%2C508&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí nos muestra un resumen de las configuraciones y que la<strong> validación ha sido superada, </strong>clic sobre <strong>Crear</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png?ssl=1" data-lbwps-width="1232" data-lbwps-height="925" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13806" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png?fit=1232%2C925&amp;ssl=1" data-orig-size="1232,925" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png?fit=640%2C481&amp;ssl=1" class="aligncenter size-full wp-image-13806" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png?resize=640%2C481&#038;ssl=1" alt="" width="640" height="481" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png?w=1232&amp;ssl=1 1232w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png?resize=595%2C447&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png?resize=960%2C721&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_5.png?resize=768%2C577&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Podemos ver que la implementación se ha completado correctamente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?ssl=1" data-lbwps-width="1581" data-lbwps-height="552" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6-1536x536.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13807" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?fit=1581%2C552&amp;ssl=1" data-orig-size="1581,552" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?fit=640%2C223&amp;ssl=1" class="aligncenter size-full wp-image-13807" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?resize=640%2C223&#038;ssl=1" alt="" width="640" height="223" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?w=1581&amp;ssl=1 1581w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?resize=595%2C208&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?resize=960%2C335&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?resize=768%2C268&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?resize=1536%2C536&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_6.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si nos vamos a Conexiones, podemos ver que ya la tenemos creada y que está conectado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?ssl=1" data-lbwps-width="1904" data-lbwps-height="702" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7-1536x566.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13808" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?fit=1904%2C702&amp;ssl=1" data-orig-size="1904,702" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?fit=640%2C236&amp;ssl=1" class="aligncenter size-full wp-image-13808" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?resize=640%2C236&#038;ssl=1" alt="" width="640" height="236" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?w=1904&amp;ssl=1 1904w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?resize=595%2C219&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?resize=960%2C354&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?resize=768%2C283&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?resize=1536%2C566&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_7.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos a la Conexión, tendremos las distintas opciones para poder configurarla y administrarla, el <strong>Estado</strong> lo muestra como <strong>Conectado</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?ssl=1" data-lbwps-width="1900" data-lbwps-height="953" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8-1536x770.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13809" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?fit=1900%2C953&amp;ssl=1" data-orig-size="1900,953" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?fit=640%2C321&amp;ssl=1" class="aligncenter size-full wp-image-13809" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?resize=640%2C321&#038;ssl=1" alt="" width="640" height="321" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?w=1900&amp;ssl=1 1900w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?resize=595%2C298&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?resize=960%2C482&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?resize=768%2C385&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?resize=1536%2C770&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos a nuestro dispositivo de VPN local (Fortigate), podemos ver que el túnel IPsec está establecido:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?ssl=1" data-lbwps-width="1795" data-lbwps-height="516" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9-1536x442.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13810" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?fit=1795%2C516&amp;ssl=1" data-orig-size="1795,516" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?fit=640%2C184&amp;ssl=1" class="aligncenter size-full wp-image-13810" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?resize=640%2C184&#038;ssl=1" alt="" width="640" height="184" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?w=1795&amp;ssl=1 1795w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?resize=595%2C171&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?resize=960%2C276&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?resize=768%2C221&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?resize=1536%2C442&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_9.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos a <strong>VPN Location Map</strong> en nuestro Fortigate, podemos ver el túnel IPsec establecido entre mi infraestructura on-premise y el Datacenter Oeste de Europa de Azure:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?ssl=1" data-lbwps-width="1897" data-lbwps-height="936" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14-1536x758.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="14135" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?fit=1897%2C936&amp;ssl=1" data-orig-size="1897,936" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?fit=640%2C316&amp;ssl=1" class="aligncenter size-full wp-image-14135" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?resize=640%2C316&#038;ssl=1" alt="" width="640" height="316" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?w=1897&amp;ssl=1 1897w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?resize=595%2C294&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?resize=960%2C474&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?resize=768%2C379&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?resize=1536%2C758&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_14.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora si hacemos un ping desde cualquier equipo de nuestra red LAN on-premise hacia una IP operativa de Azure, podemos ver, que tenemos conexión, esta IP es una de las que Azure se reserva para la Subred de puerta de enlace:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_11.png?ssl=1" data-lbwps-width="652" data-lbwps-height="346" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13812" data-permalink="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/azcdlcvpns2sea_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_11.png?fit=652%2C346&amp;ssl=1" data-orig-size="652,346" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="azcdlcvpns2sea_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_11.png?fit=640%2C340&amp;ssl=1" class="aligncenter size-full wp-image-13812" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_11.png?resize=640%2C340&#038;ssl=1" alt="" width="640" height="340" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_11.png?w=652&amp;ssl=1 652w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/azcdlcvpns2sea_11.png?resize=595%2C316&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13801</post-id>	</item>
		<item>
		<title>AZURE – Configuración VPN Site to Site en dispositivo Fortigate</title>
		<link>https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate</link>
					<comments>https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Wed, 22 Sep 2021 09:24:31 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=13780</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver como configurar una VPN Site to Site en un dispositivo Fortigate. En nuestro Fortigate nos vamos a VPN &#62; Asistente IPsec &#62; Personalizar, le indicamos un nombre y siguiente: Configuramos los&#8230; <a href="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver como configurar una VPN Site to Site en un dispositivo Fortigate.</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_1.png?ssl=1" data-lbwps-width="755" data-lbwps-height="276" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13781" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_1.png?fit=755%2C276&amp;ssl=1" data-orig-size="755,276" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_1.png?fit=640%2C234&amp;ssl=1" class="aligncenter size-full wp-image-13781" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_1.png?resize=640%2C234&#038;ssl=1" alt="" width="640" height="234" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_1.png?w=755&amp;ssl=1 755w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_1.png?resize=595%2C218&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En nuestro Fortigate nos vamos a <strong>VPN &gt; Asistente IPsec &gt; Personalizar</strong>, le indicamos un<strong> nombre</strong> y <strong>siguiente</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png?ssl=1" data-lbwps-width="1290" data-lbwps-height="510" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13782" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png?fit=1290%2C510&amp;ssl=1" data-orig-size="1290,510" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png?fit=640%2C253&amp;ssl=1" class="aligncenter size-full wp-image-13782" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png?resize=640%2C253&#038;ssl=1" alt="" width="640" height="253" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png?w=1290&amp;ssl=1 1290w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png?resize=595%2C235&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png?resize=960%2C380&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_2.png?resize=768%2C304&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos los <strong>ajustes de red</strong>:</li>
</ul>
<ul>
<li>Para <strong>Puerta de enlace remota</strong>, seleccionamos <strong>Dirección IP estática</strong> e ingresamos la dirección IP proporcionada por Azure.</li>
<li>Para <strong>Interfaz</strong>, seleccionamos wan1</li>
<li>Para <strong>NAT Traversal</strong>, seleccionamos <strong>Desactivar</strong></li>
<li>Para<strong> Dead Peer Detection (Detección de punto remoto inalcanzable)</strong>, seleccionamos <strong>On Idle (Ocioso)</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_3.png?ssl=1" data-lbwps-width="939" data-lbwps-height="643" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13783" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_3.png?fit=939%2C643&amp;ssl=1" data-orig-size="939,643" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_3.png?fit=640%2C438&amp;ssl=1" class="aligncenter size-full wp-image-13783" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_3.png?resize=640%2C438&#038;ssl=1" alt="" width="640" height="438" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_3.png?w=939&amp;ssl=1 939w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_3.png?resize=595%2C407&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_3.png?resize=768%2C526&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos los <strong>ajustes de autenticación</strong>:</li>
<li>En <strong>Método</strong>, seleccionamos Llave Compartida e ingresamos la Clave.</li>
<li>Para <strong>IKE</strong>, seleccionamos la versión 2.</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_4.png?ssl=1" data-lbwps-width="928" data-lbwps-height="433" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13784" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_4.png?fit=928%2C433&amp;ssl=1" data-orig-size="928,433" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_4.png?fit=640%2C299&amp;ssl=1" class="aligncenter size-full wp-image-13784" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_4.png?resize=640%2C299&#038;ssl=1" alt="" width="640" height="299" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_4.png?w=928&amp;ssl=1 928w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_4.png?resize=595%2C278&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_4.png?resize=768%2C358&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Configuramos los ajustes de la propuesta de fase 1 .</li>
</ul>
<ul>
<li>Establezcemos la <strong>combinación de cifrado y autenticación</strong> en las tres combinaciones de algoritmos de cifrado admitidas aceptadas por Azure.
<ul>
<li>AES256 y SHA1</li>
<li>3DES y SHA1</li>
<li>AES256 y SHA256</li>
</ul>
</li>
<li>Para Grupos <strong>Diffie-Hellman</strong>, seleccionamos 2.</li>
<li>Establezcemos el <strong>Key Lifetime (segundos)</strong> en<strong> 28800</strong>.</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_5.png?ssl=1" data-lbwps-width="961" data-lbwps-height="419" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13785" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_5.png?fit=961%2C419&amp;ssl=1" data-orig-size="961,419" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_5.png?fit=640%2C279&amp;ssl=1" class="aligncenter size-full wp-image-13785" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_5.png?resize=640%2C279&#038;ssl=1" alt="" width="640" height="279" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_5.png?w=961&amp;ssl=1 961w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_5.png?resize=595%2C259&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_5.png?resize=768%2C335&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En <strong>Selectores de Fase 2</strong>, expanda la sección <strong>Avanzado </strong>para configurar los ajustes de <strong>Propuesta de Fase 2</strong>.</li>
<li>Configuramos las combinaciones de <strong>cifrado y autenticación</strong>:</li>
</ul>
<ul>
<li style="list-style-type: none;">
<ul>
<li>AES256 y SHA1</li>
<li>3DES y SHA1</li>
<li>AES256 y SHA256</li>
</ul>
</li>
</ul>
<ul>
<li>Desmarcamos <strong>Habilitar Perfect Forward Secrecy (PFS)</strong>.</li>
<li>Establezcemos el <strong>Key Lifetime (segundos)</strong>en <strong>27000</strong>.</li>
<li>Clic a OK.</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png?ssl=1" data-lbwps-width="1257" data-lbwps-height="950" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13786" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png?fit=1257%2C950&amp;ssl=1" data-orig-size="1257,950" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png?fit=640%2C484&amp;ssl=1" class="aligncenter size-full wp-image-13786" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png?resize=640%2C484&#038;ssl=1" alt="" width="640" height="484" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png?w=1257&amp;ssl=1 1257w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png?resize=595%2C450&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png?resize=960%2C726&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_6.png?resize=768%2C580&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, aquí tenemos el Túnel IPsec creado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?ssl=1" data-lbwps-width="1620" data-lbwps-height="422" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7-1536x400.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13787" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?fit=1620%2C422&amp;ssl=1" data-orig-size="1620,422" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?fit=640%2C167&amp;ssl=1" class="aligncenter size-full wp-image-13787" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?resize=640%2C167&#038;ssl=1" alt="" width="640" height="167" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?w=1620&amp;ssl=1 1620w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?resize=595%2C155&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?resize=960%2C250&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?resize=768%2C200&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?resize=1536%2C400&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_7.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a crear el objeto direcciones con el espacio de direcciones que tenemos configurado en la Red Virtual de Azure, para ello, accedemos a <strong>Políticas y Objetos &gt; Dirección &gt; Crear nuevo &gt; Dirección</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_8.png?ssl=1" data-lbwps-width="776" data-lbwps-height="417" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13788" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_8.png?fit=776%2C417&amp;ssl=1" data-orig-size="776,417" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_8.png?fit=640%2C344&amp;ssl=1" class="aligncenter size-full wp-image-13788" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_8.png?resize=640%2C344&#038;ssl=1" alt="" width="640" height="344" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_8.png?w=776&amp;ssl=1 776w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_8.png?resize=595%2C320&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_8.png?resize=768%2C413&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Le indicamos un nombre, la subred y la interface:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png?ssl=1" data-lbwps-width="1244" data-lbwps-height="723" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13789" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png?fit=1244%2C723&amp;ssl=1" data-orig-size="1244,723" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png?fit=640%2C372&amp;ssl=1" class="aligncenter size-full wp-image-13789" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png?resize=640%2C372&#038;ssl=1" alt="" width="640" height="372" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png?w=1244&amp;ssl=1 1244w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png?resize=595%2C346&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png?resize=960%2C558&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_9.png?resize=768%2C446&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver ya tenemos el objeto dirección creado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?ssl=1" data-lbwps-width="1869" data-lbwps-height="404" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10-1536x332.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13790" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?fit=1869%2C404&amp;ssl=1" data-orig-size="1869,404" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?fit=640%2C139&amp;ssl=1" class="aligncenter size-full wp-image-13790" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?resize=640%2C138&#038;ssl=1" alt="" width="640" height="138" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?w=1869&amp;ssl=1 1869w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?resize=595%2C129&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?resize=960%2C208&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?resize=768%2C166&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?resize=1536%2C332&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_10.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a crear las <strong>políticas</strong>:</li>
</ul>
<ul>
<li>Accedemos a <strong>Políticas y objetos&gt; Política IPv4 &gt; Crear nuevo</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_11.png?ssl=1" data-lbwps-width="952" data-lbwps-height="439" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13791" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_11.png?fit=952%2C439&amp;ssl=1" data-orig-size="952,439" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_11.png?fit=640%2C295&amp;ssl=1" class="aligncenter size-full wp-image-13791" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_11.png?resize=640%2C295&#038;ssl=1" alt="" width="640" height="295" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_11.png?w=952&amp;ssl=1 952w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_11.png?resize=595%2C274&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_11.png?resize=768%2C354&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Creamos una política para la conexión de sitio a sitio que permita el tráfico saliente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png?ssl=1" data-lbwps-width="1241" data-lbwps-height="948" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13792" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png?fit=1241%2C948&amp;ssl=1" data-orig-size="1241,948" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png?fit=640%2C489&amp;ssl=1" class="aligncenter size-full wp-image-13792" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png?resize=640%2C489&#038;ssl=1" alt="" width="640" height="489" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png?w=1241&amp;ssl=1 1241w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png?resize=595%2C455&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png?resize=960%2C733&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_12.png?resize=768%2C587&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Creamos otra política para la conexión de sitio a sitio que permita el tráfico entrante:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png?ssl=1" data-lbwps-width="1242" data-lbwps-height="950" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13793" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png?fit=1242%2C950&amp;ssl=1" data-orig-size="1242,950" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png?fit=640%2C489&amp;ssl=1" class="aligncenter size-full wp-image-13793" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png?resize=640%2C490&#038;ssl=1" alt="" width="640" height="490" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png?w=1242&amp;ssl=1 1242w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png?resize=595%2C455&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png?resize=960%2C734&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_13.png?resize=768%2C587&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí podemos ver las políticas creadas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?ssl=1" data-lbwps-width="1869" data-lbwps-height="314" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14-1536x258.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13794" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?fit=1869%2C314&amp;ssl=1" data-orig-size="1869,314" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?fit=640%2C107&amp;ssl=1" class="aligncenter size-full wp-image-13794" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?resize=640%2C108&#038;ssl=1" alt="" width="640" height="108" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?w=1869&amp;ssl=1 1869w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?resize=595%2C100&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?resize=960%2C161&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?resize=768%2C129&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?resize=1536%2C258&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_14.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?ssl=1" data-lbwps-width="1882" data-lbwps-height="278" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15-1536x227.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13795" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?fit=1882%2C278&amp;ssl=1" data-orig-size="1882,278" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?fit=640%2C95&amp;ssl=1" class="aligncenter size-full wp-image-13795" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?resize=640%2C95&#038;ssl=1" alt="" width="640" height="95" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?w=1882&amp;ssl=1 1882w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?resize=595%2C88&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?resize=960%2C142&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?resize=768%2C113&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?resize=1536%2C227&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_15.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a limitar el tamaño máximo de segmento de TCP (MSS) que se envía y recibe para evitar la caída y la fragmentación de paquetes, para hacer esto, usaremos los siguientes comandos CLI en ambas políticas:</li>
</ul>
<p><em>config firewall policy</em></p>
<p><em>   edit &lt;policy-id&gt;</em></p>
<p><em>      set tcp-mss-sender 1350</em></p>
<p><em>      set tcp-mss-receiver 1350</em></p>
<p><em>   next</em></p>
<p><em>end</em></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_16.png?ssl=1" data-lbwps-width="579" data-lbwps-height="475" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13796" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_16.png?fit=579%2C475&amp;ssl=1" data-orig-size="579,475" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_16.png?fit=579%2C475&amp;ssl=1" class="aligncenter size-full wp-image-13796" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_16.png?resize=579%2C475&#038;ssl=1" alt="" width="579" height="475" /></a></p>
<ul>
<li>Para terminar, vamos a crear una ruta estática que obligue al tráfico saliente que va a Azure, a pasar por el túnel basado en rutas, para ello accedemos a <strong>Red &gt; Ruta Estática &gt; Crear nuevo</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?ssl=1" data-lbwps-width="1767" data-lbwps-height="465" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17-1536x404.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13797" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?fit=1767%2C465&amp;ssl=1" data-orig-size="1767,465" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?fit=640%2C169&amp;ssl=1" class="aligncenter size-full wp-image-13797" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?resize=640%2C168&#038;ssl=1" alt="" width="640" height="168" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?w=1767&amp;ssl=1 1767w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?resize=595%2C157&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?resize=960%2C253&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?resize=768%2C202&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?resize=1536%2C404&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_17.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png?ssl=1" data-lbwps-width="1240" data-lbwps-height="449" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13798" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png?fit=1240%2C449&amp;ssl=1" data-orig-size="1240,449" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png?fit=640%2C232&amp;ssl=1" class="aligncenter size-full wp-image-13798" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png?resize=640%2C232&#038;ssl=1" alt="" width="640" height="232" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png?w=1240&amp;ssl=1 1240w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png?resize=595%2C215&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png?resize=960%2C348&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_18.png?resize=768%2C278&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?ssl=1" data-lbwps-width="1817" data-lbwps-height="453" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19-1536x383.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13799" data-permalink="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/acvpns2senftg_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?fit=1817%2C453&amp;ssl=1" data-orig-size="1817,453" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="acvpns2senftg_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?fit=640%2C159&amp;ssl=1" class="aligncenter size-full wp-image-13799" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?resize=640%2C160&#038;ssl=1" alt="" width="640" height="160" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?w=1817&amp;ssl=1 1817w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?resize=595%2C148&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?resize=960%2C239&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?resize=768%2C191&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?resize=1536%2C383&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/acvpns2senftg_19.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con esto, hemos terminado de configurar la VPN en nuestro dispositivo Fortigate, ahora nos quedaría configurar la conexión en Azure.</li>
</ul>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate/feed</wfw:commentRss>
			<slash:comments>7</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13780</post-id>	</item>
		<item>
		<title>AZURE – VPN Site to Site entre Azure y nuestro entorno on-premise</title>
		<link>https://blog.ragasys.es/azure-vpn-site-to-site-entre-azure-y-nuestro-entorno-on-premise</link>
					<comments>https://blog.ragasys.es/azure-vpn-site-to-site-entre-azure-y-nuestro-entorno-on-premise#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Wed, 15 Sep 2021 07:36:29 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=13760</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver como desplegar y configurar una VPN Site to Site entre nuestra infraestructura montada en Azure y nuestro entorno on-premise, este post lo vamos a dividir en tres partes: Configuración VPN Site&#8230; <a href="https://blog.ragasys.es/azure-vpn-site-to-site-entre-azure-y-nuestro-entorno-on-premise" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver como desplegar y configurar una VPN Site to Site entre nuestra infraestructura montada en Azure y nuestro entorno on-premise, este post lo vamos a dividir en tres partes:</p>
<ul>
<li><a href="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-azure" target="_blank" rel="noopener">Configuración VPN Site to Site en Azure</a></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_1.png?ssl=1" data-lbwps-width="740" data-lbwps-height="188" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13761" data-permalink="https://blog.ragasys.es/azure-vpn-site-to-site-entre-azure-y-nuestro-entorno-on-premise/avpns2seayneop_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_1.png?fit=740%2C188&amp;ssl=1" data-orig-size="740,188" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="avpns2seayneop_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_1.png?fit=640%2C163&amp;ssl=1" class="aligncenter size-full wp-image-13761" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_1.png?resize=640%2C163&#038;ssl=1" alt="" width="640" height="163" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_1.png?w=740&amp;ssl=1 740w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_1.png?resize=595%2C151&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li><a href="https://blog.ragasys.es/azure-configuracion-vpn-site-to-site-en-dispositivo-fortigate" target="_blank" rel="noopener">Configuración VPN Site to Site en dispositivo Fortigate</a></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_2.png?ssl=1" data-lbwps-width="755" data-lbwps-height="276" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13762" data-permalink="https://blog.ragasys.es/azure-vpn-site-to-site-entre-azure-y-nuestro-entorno-on-premise/avpns2seayneop_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_2.png?fit=755%2C276&amp;ssl=1" data-orig-size="755,276" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="avpns2seayneop_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_2.png?fit=640%2C234&amp;ssl=1" class="aligncenter size-full wp-image-13762" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_2.png?resize=640%2C234&#038;ssl=1" alt="" width="640" height="234" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_2.png?w=755&amp;ssl=1 755w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/09/avpns2seayneop_2.png?resize=595%2C218&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li><a href="https://blog.ragasys.es/azure-creacion-de-la-conexion-vpn-site-to-site-en-azure" target="_blank" rel="noopener">Creación de la conexión VPN Site to Site en Azure</a></li>
</ul>
<p>En las próximas semanas iremos subiendo estos tres post.</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/azure-vpn-site-to-site-entre-azure-y-nuestro-entorno-on-premise/feed</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13760</post-id>	</item>
		<item>
		<title>Fortigate &#8211; HA &#8211; Interfaces Virtuales Para Management</title>
		<link>https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management</link>
					<comments>https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 26 Apr 2021 07:34:25 +0000</pubDate>
				<category><![CDATA[Cluster]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[HA]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Routing]]></category>
		<category><![CDATA[Switching]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=13325</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver como configurar las interfaces virtuales para administración en un cluster HA con dispositivos Fortigate, en un post anterior vimos como configurar interfaces dedicadas de management utilizando un puerto físico del dispositivo,&#8230; <a href="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver como configurar las interfaces virtuales para administración en un cluster HA con dispositivos Fortigate, en un post anterior vimos como configurar interfaces dedicadas de management utilizando un puerto físico del dispositivo, en muchas ocasiones, podemos encontrarnos con dispositivos Fortigates con pocas interfaces físicas, y si queremos un puerto dedicado para administración, entonces lo mejor es configurar estas interfaces virtuales, utilizando un puerto físico que ya tenemos en uso.</p>
<ul>
<li>Lo primero que tenemos que hacer es acceder a <strong>System &gt; HA</strong> <strong>&gt; Fortigate Primario &gt; Editar</strong> y verificar que <strong>Management Interface Reservation</strong> está deshabilitado en nuestro cluster:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="409" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1-1536x328.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13326" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?fit=1915%2C409&amp;ssl=1" data-orig-size="1915,409" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?fit=640%2C137&amp;ssl=1" class="aligncenter size-full wp-image-13326" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?resize=640%2C137&#038;ssl=1" alt="" width="640" height="137" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?resize=595%2C127&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?resize=960%2C205&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?resize=768%2C164&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?resize=1536%2C328&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_1.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png?ssl=1" data-lbwps-width="1248" data-lbwps-height="718" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13327" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png?fit=1248%2C718&amp;ssl=1" data-orig-size="1248,718" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png?fit=640%2C368&amp;ssl=1" class="aligncenter size-full wp-image-13327" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png?resize=640%2C368&#038;ssl=1" alt="" width="640" height="368" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png?w=1248&amp;ssl=1 1248w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png?resize=595%2C342&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png?resize=960%2C552&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_2.png?resize=768%2C442&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para configurar las interfaces virtuales debemos de acceder por consola:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?ssl=1" data-lbwps-width="1911" data-lbwps-height="358" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3-1536x288.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13328" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?fit=1911%2C358&amp;ssl=1" data-orig-size="1911,358" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?fit=640%2C120&amp;ssl=1" class="aligncenter size-full wp-image-13328" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?resize=640%2C120&#038;ssl=1" alt="" width="640" height="120" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?w=1911&amp;ssl=1 1911w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?resize=595%2C111&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?resize=960%2C180&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?resize=768%2C144&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?resize=1536%2C288&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ejecutamos el comando <strong>system config interface</strong> y editamos el puerto 10 con <strong>edit port10:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_4.png?ssl=1" data-lbwps-width="857" data-lbwps-height="218" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13329" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_4.png?fit=857%2C218&amp;ssl=1" data-orig-size="857,218" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_4.png?fit=640%2C163&amp;ssl=1" class="aligncenter size-full wp-image-13329" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_4.png?resize=640%2C163&#038;ssl=1" alt="" width="640" height="163" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_4.png?w=857&amp;ssl=1 857w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_4.png?resize=595%2C151&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_4.png?resize=768%2C195&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Le hacemos un <strong>get </strong>y cómo podemos ver tenemos la opción de configurar el <strong>management-ip</strong>, esta IP virtual no se va a sincronizar entre los dispositivos del cluster:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_5.png?ssl=1" data-lbwps-width="851" data-lbwps-height="707" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13330" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_5.png?fit=851%2C707&amp;ssl=1" data-orig-size="851,707" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_5.png?fit=640%2C532&amp;ssl=1" class="aligncenter size-full wp-image-13330" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_5.png?resize=640%2C532&#038;ssl=1" alt="" width="640" height="532" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_5.png?w=851&amp;ssl=1 851w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_5.png?resize=595%2C494&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_5.png?resize=768%2C638&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora con el comando <strong>set management-ip 192.168.14.225 255.255.255.0 </strong>le vamos a asignar al dispositivo con el rol primario del cluster, una dirección IP virtual que utilizaremos para la gestión y administración del dispositivo:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_6.png?ssl=1" data-lbwps-width="762" data-lbwps-height="854" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13331" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_6.png?fit=762%2C854&amp;ssl=1" data-orig-size="762,854" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_6.png?fit=640%2C717&amp;ssl=1" class="aligncenter size-full wp-image-13331" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_6.png?resize=640%2C717&#038;ssl=1" alt="" width="640" height="717" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_6.png?w=762&amp;ssl=1 762w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_6.png?resize=595%2C667&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si le hacemos un <strong>get</strong> podemos ver que ya tiene la IP virtual configurada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_7.png?ssl=1" data-lbwps-width="706" data-lbwps-height="352" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13332" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_7.png?fit=706%2C352&amp;ssl=1" data-orig-size="706,352" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_7.png?fit=640%2C319&amp;ssl=1" class="aligncenter size-full wp-image-13332" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_7.png?resize=640%2C319&#038;ssl=1" alt="" width="640" height="319" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_7.png?w=706&amp;ssl=1 706w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_7.png?resize=595%2C297&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con <strong>end</strong> salimos y guardamos los cambios:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_8.png?ssl=1" data-lbwps-width="554" data-lbwps-height="862" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13333" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_8.png?fit=554%2C862&amp;ssl=1" data-orig-size="554,862" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_8.png?fit=554%2C862&amp;ssl=1" class="aligncenter size-full wp-image-13333" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_8.png?resize=554%2C862&#038;ssl=1" alt="" width="554" height="862" /></a></p>
<ul>
<li>Ahora ya podemos acceder a través de la IP de management virtual sobre el Fortigate01:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?ssl=1" data-lbwps-width="1912" data-lbwps-height="518" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9-1536x416.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13334" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?fit=1912%2C518&amp;ssl=1" data-orig-size="1912,518" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?fit=640%2C173&amp;ssl=1" class="aligncenter size-full wp-image-13334" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?resize=640%2C173&#038;ssl=1" alt="" width="640" height="173" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?w=1912&amp;ssl=1 1912w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?resize=595%2C161&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?resize=960%2C260&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?resize=768%2C208&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?resize=1536%2C416&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_9.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a configurar la interface de management virtual del Fortigate que tiene el rol de secundario, para ello nos abrimos una consola CLI y ejecutamos el comando <strong>execute ha manage 0 admin </strong>para acceder al dispositivo con el rol de secundario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_10.png?ssl=1" data-lbwps-width="787" data-lbwps-height="254" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13335" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_10.png?fit=787%2C254&amp;ssl=1" data-orig-size="787,254" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_10.png?fit=640%2C207&amp;ssl=1" class="aligncenter size-full wp-image-13335" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_10.png?resize=640%2C207&#038;ssl=1" alt="" width="640" height="207" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_10.png?w=787&amp;ssl=1 787w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_10.png?resize=595%2C192&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_10.png?resize=768%2C248&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ejecutamos el comando <strong>system config interface</strong> y editamos el puerto 10 con <strong>edit port10:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_11.png?ssl=1" data-lbwps-width="615" data-lbwps-height="230" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13336" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_11.png?fit=615%2C230&amp;ssl=1" data-orig-size="615,230" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_11.png?fit=615%2C230&amp;ssl=1" class="aligncenter size-full wp-image-13336" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_11.png?resize=615%2C230&#038;ssl=1" alt="" width="615" height="230" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_11.png?w=615&amp;ssl=1 615w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_11.png?resize=595%2C223&amp;ssl=1 595w" sizes="auto, (max-width: 615px) 100vw, 615px" /></a></p>
<ul>
<li>Le hacemos un <strong>get </strong>y cómo podemos ver tenemos la opción de configurar el <strong>management-ip</strong>, esta IP virtual no se va a sincronizar entre los dispositivos del cluster:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_12.png?ssl=1" data-lbwps-width="719" data-lbwps-height="852" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13337" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_12.png?fit=719%2C852&amp;ssl=1" data-orig-size="719,852" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_12.png?fit=640%2C758&amp;ssl=1" class="aligncenter size-full wp-image-13337" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_12.png?resize=640%2C758&#038;ssl=1" alt="" width="640" height="758" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_12.png?w=719&amp;ssl=1 719w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_12.png?resize=595%2C705&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora con el comando <strong>set management-ip 192.168.14.226 255.255.255.0 </strong>le vamos a asignar al dispositivo con el rol secundario del cluster, una dirección IP virtual que utilizaremos para la gestión y administración del dispositivo:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_13.png?ssl=1" data-lbwps-width="776" data-lbwps-height="827" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13338" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_13.png?fit=776%2C827&amp;ssl=1" data-orig-size="776,827" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_13.png?fit=640%2C682&amp;ssl=1" class="aligncenter size-full wp-image-13338" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_13.png?resize=640%2C682&#038;ssl=1" alt="" width="640" height="682" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_13.png?w=776&amp;ssl=1 776w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_13.png?resize=595%2C634&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_13.png?resize=768%2C818&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si le hacemos un <strong>get</strong> podemos ver que ya tiene la IP virtual configurada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_14.png?ssl=1" data-lbwps-width="753" data-lbwps-height="330" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13339" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_14.png?fit=753%2C330&amp;ssl=1" data-orig-size="753,330" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_14.png?fit=640%2C280&amp;ssl=1" class="aligncenter size-full wp-image-13339" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_14.png?resize=640%2C280&#038;ssl=1" alt="" width="640" height="280" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_14.png?w=753&amp;ssl=1 753w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_14.png?resize=595%2C261&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con <strong>end</strong> salimos y guardamos los cambios:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_15.png?ssl=1" data-lbwps-width="562" data-lbwps-height="859" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13340" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_15.png?fit=562%2C859&amp;ssl=1" data-orig-size="562,859" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_15.png?fit=562%2C859&amp;ssl=1" class="aligncenter size-full wp-image-13340" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_15.png?resize=562%2C859&#038;ssl=1" alt="" width="562" height="859" /></a></p>
<ul>
<li>Ahora ya podemos acceder a través de la IP de management virtual sobre el Fortigate02:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="507" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16-1536x407.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13341" data-permalink="https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/fghaivpmngmt_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?fit=1915%2C507&amp;ssl=1" data-orig-size="1915,507" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fghaivpmngmt_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?fit=640%2C169&amp;ssl=1" class="aligncenter size-full wp-image-13341" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?resize=640%2C169&#038;ssl=1" alt="" width="640" height="169" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?resize=595%2C158&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?resize=960%2C254&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?resize=768%2C203&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?resize=1536%2C407&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fghaivpmngmt_16.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/fortigate-ha-interfaces-virtuales-para-management/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13325</post-id>	</item>
		<item>
		<title>Fortigate HA ACTIVO – ACTIVO</title>
		<link>https://blog.ragasys.es/fortigate-ha-activo-activo</link>
					<comments>https://blog.ragasys.es/fortigate-ha-activo-activo#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Thu, 22 Apr 2021 08:33:08 +0000</pubDate>
				<category><![CDATA[Cluster]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[HA]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Routing]]></category>
		<category><![CDATA[Switching]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=13280</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver como configurar dos Firewall Fortigate en HA (Alta Disponibilidad) en modo Activo-Activo: Vamos a utilizar dos Interfaces de cada dispositivo para HA para vincularlos y sincronizarlos. En HA uno de los&#8230; <a href="https://blog.ragasys.es/fortigate-ha-activo-activo" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver como configurar dos Firewall Fortigate en HA (Alta Disponibilidad) en modo Activo-Activo:</p>
<ul>
<li>Vamos a utilizar dos Interfaces de cada dispositivo para HA para vincularlos y sincronizarlos.</li>
<li>En HA uno de los Fortigate estará como primario y éste sincronizará su información con el otro Fortigate que será el secundario.</li>
<li>El link para el HA entre los Fortigate, que en este caso usaremos dos (HA1 y HA2) se llama Heartbeat y se utiliza para la sincronización y detección entre los equipos.</li>
<li>Tenemos dos modos de configurar HA: Activo-Pasivo y Activo-Activo.</li>
</ul>
<p>En este segundo post vamos a ver el modo Activo-Activo, en este modo todos los dispositivos procesan tráfico, pero seguimos teniendo un dispositivo que actúa como primario y otro como secundario, el dispositivo primario se encarga de distribuir todas las sesiones en el cluster, pero si el primario cae, entonces el secundario pasaría a tener el rol de primario.</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png?ssl=1" data-lbwps-width="998" data-lbwps-height="383" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13281" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png?fit=998%2C383&amp;ssl=1" data-orig-size="998,383" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png?fit=640%2C245&amp;ssl=1" class="aligncenter size-full wp-image-13281" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png?resize=640%2C246&#038;ssl=1" alt="" width="640" height="246" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png?w=998&amp;ssl=1 998w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png?resize=595%2C228&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png?resize=960%2C368&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_1.png?resize=768%2C295&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>Vamos a ver que necesitamos para crear y configurar un cluster HA en Firewall FortiGates:</p>
<ul>
<li>Dos Fortigates del mismo modelo</li>
<li>Misma versión de FortiOS en ambos equipos</li>
<li>Mismas licencias</li>
<li>Un link entre los equipos que componen el cluster HA, en este caso vamos a utilizar dos</li>
<li>Las mismas interfaces deben de estar conectadas al mismo dominio de broadcast, es decir, los puertos usados deben de ser los mismos en ambos dispositivos y conectados en el mismo segmento de red.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Para empezar con la configuración de nuestro cluster HA Activo-Activo, vamos a realizar las configuraciones básicas sobre uno de nuestros Fortigate, que actuará como primario, el otro Fortigate lo dejamos con las configuraciones de fábrica, <a href="https://blog.ragasys.es/fortigate-configuracion-inicial-y-puesta-en-marcha" target="_blank" rel="noopener">en este link podemos ver la configuración inicial y puesta en marcha</a>.</li>
<li>Aquí vemos como tenemos configurado el hostname y las interfaces de red del primer Fortigate (LAN y WAN):</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png?ssl=1" data-lbwps-width="964" data-lbwps-height="573" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13282" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png?fit=964%2C573&amp;ssl=1" data-orig-size="964,573" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png?fit=640%2C381&amp;ssl=1" class="aligncenter size-full wp-image-13282" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png?resize=640%2C380&#038;ssl=1" alt="" width="640" height="380" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png?w=964&amp;ssl=1 964w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png?resize=595%2C354&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png?resize=960%2C571&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_2.png?resize=768%2C456&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?ssl=1" data-lbwps-width="1389" data-lbwps-height="785" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13283" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?fit=1389%2C785&amp;ssl=1" data-orig-size="1389,785" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?fit=640%2C362&amp;ssl=1" class="aligncenter size-full wp-image-13283" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?resize=640%2C362&#038;ssl=1" alt="" width="640" height="362" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?w=1389&amp;ssl=1 1389w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?resize=595%2C336&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?resize=960%2C543&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?resize=768%2C434&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Del segundo Fortigate, está tal y como viene de fábrica:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?ssl=1" data-lbwps-width="1895" data-lbwps-height="757" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4-1536x614.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13284" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?fit=1895%2C757&amp;ssl=1" data-orig-size="1895,757" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?fit=640%2C255&amp;ssl=1" class="aligncenter size-full wp-image-13284" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?resize=640%2C256&#038;ssl=1" alt="" width="640" height="256" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?w=1895&amp;ssl=1 1895w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?resize=595%2C238&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?resize=960%2C383&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?resize=768%2C307&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?resize=1536%2C614&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_4.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo primero que vamos a realizar es configurar sobre el Fortigate01 el nombre de las interfaces de red que van a participar en el cluster HA, se llaman interfaces de Heartbeat y se utilizan para la sincronización y detección entre los equipos, utilizaremos los puertos 4 y 5:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?ssl=1" data-lbwps-width="1419" data-lbwps-height="793" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13285" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?fit=1419%2C793&amp;ssl=1" data-orig-size="1419,793" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?fit=640%2C357&amp;ssl=1" class="aligncenter size-full wp-image-13285" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?resize=640%2C358&#038;ssl=1" alt="" width="640" height="358" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?w=1419&amp;ssl=1 1419w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?resize=595%2C333&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?resize=960%2C536&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?resize=768%2C429&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_5.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora sobre <strong>System &gt; HA &gt; </strong>seleccionamos el modo que nos interese, en este caso<strong> Active-Active:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png?ssl=1" data-lbwps-width="1253" data-lbwps-height="712" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13286" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png?fit=1253%2C712&amp;ssl=1" data-orig-size="1253,712" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png?fit=640%2C364&amp;ssl=1" class="aligncenter size-full wp-image-13286" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png?resize=640%2C364&#038;ssl=1" alt="" width="640" height="364" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png?w=1253&amp;ssl=1 1253w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png?resize=595%2C338&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png?resize=960%2C546&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_6.png?resize=768%2C436&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>High Availability </strong>le indicamos el modo y la prioridad, sobre <strong>Cluster Settings </strong>le damos un nombre al cluster, le asignamos un password, habilitamos <strong>Session pickup</strong> para que automáticamente se pasen las sesiones de un Fortigate a otro y así los clientes no tengan que volver a reconectarse, el <strong>Monitor interfaces</strong> lo vamos a habilitar más adelante y explicaremos de que se trata y sobre <strong>Heartbeat Interfaces</strong> vamos a configurar las interfaces que van a participar en el cluster HA, sobre <strong>Heartbeat Interface Priority </strong>vamos a configurar las prioridades de las interfaces de Heartbeat, que en este caso el port4 va a tener prioridad sobre el port5:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png?ssl=1" data-lbwps-width="1247" data-lbwps-height="722" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13287" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png?fit=1247%2C722&amp;ssl=1" data-orig-size="1247,722" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png?fit=640%2C371&amp;ssl=1" class="aligncenter size-full wp-image-13287" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png?resize=640%2C371&#038;ssl=1" alt="" width="640" height="371" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png?w=1247&amp;ssl=1 1247w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png?resize=595%2C344&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png?resize=960%2C556&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_7.png?resize=768%2C445&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora podemos ver que en <strong>System &gt; HA</strong> nos muestra los puertos 4 y 5 con un corazón indicando que son los puertos de Heartbeat para el cluster:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="636" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8-1536x510.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13288" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?fit=1915%2C636&amp;ssl=1" data-orig-size="1915,636" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?fit=640%2C213&amp;ssl=1" class="aligncenter size-full wp-image-13288" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?resize=640%2C213&#038;ssl=1" alt="" width="640" height="213" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?resize=595%2C198&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?resize=960%2C319&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?resize=768%2C255&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?resize=1536%2C510&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre el Fortigate01 ya tenemos las configuraciones de HA realizadas, ahora debemos de configurar el Fortigate02, y como el nombre del host no se sincroniza, es lo primero que tenemos que configurar, en <strong>System &gt; Settings</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png?ssl=1" data-lbwps-width="1293" data-lbwps-height="950" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13289" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png?fit=1293%2C950&amp;ssl=1" data-orig-size="1293,950" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png?fit=640%2C470&amp;ssl=1" class="aligncenter size-full wp-image-13289" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png?resize=640%2C470&#038;ssl=1" alt="" width="640" height="470" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png?w=1293&amp;ssl=1 1293w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png?resize=595%2C437&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png?resize=960%2C705&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_9.png?resize=768%2C564&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora sobre <strong>System &gt; HA</strong> realizamos las mismas configuraciones que hemos hecho sobre el Fortigate01, excepto que en la prioridad del dispositivo la vamos a bajar a 100, clic sobre OK:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png?ssl=1" data-lbwps-width="1247" data-lbwps-height="733" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13290" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png?fit=1247%2C733&amp;ssl=1" data-orig-size="1247,733" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png?fit=640%2C376&amp;ssl=1" class="aligncenter size-full wp-image-13290" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png?resize=640%2C376&#038;ssl=1" alt="" width="640" height="376" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png?w=1247&amp;ssl=1 1247w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png?resize=595%2C350&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png?resize=960%2C564&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_10.png?resize=768%2C451&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, perdemos conexión con nuestro Fortigate02, ya que la dirección IP que tenía, ha desaparecido al unirlo al cluster, ahora estos dos dispositivos es como si fuesen uno solo y los dos van a tener las mismas configuraciones:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png?ssl=1" data-lbwps-width="1314" data-lbwps-height="711" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13291" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png?fit=1314%2C711&amp;ssl=1" data-orig-size="1314,711" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png?fit=640%2C346&amp;ssl=1" class="aligncenter size-full wp-image-13291" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png?resize=640%2C346&#038;ssl=1" alt="" width="640" height="346" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png?w=1314&amp;ssl=1 1314w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png?resize=595%2C322&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png?resize=960%2C519&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_11.png?resize=768%2C416&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre el Fortigate01 accedemos a <strong>System &gt; HA </strong>y podemos ver que ya tenemos el segundo dispositivo unido al cluster, aunque todavía está sincronizando, esto nos lo muestra muy claro el checksum, que como podemos observar, son números diferentes, ya que al no estar sincronizados todavía cada dispositivo tiene una configuración:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="641" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12-1536x514.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13292" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?fit=1915%2C641&amp;ssl=1" data-orig-size="1915,641" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?fit=640%2C214&amp;ssl=1" class="aligncenter size-full wp-image-13292" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?resize=640%2C214&#038;ssl=1" alt="" width="640" height="214" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?resize=595%2C199&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?resize=960%2C321&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?resize=768%2C257&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?resize=1536%2C514&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_12.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Pasados unos minutos, ya podemos ver que los dos dispositivos están sincronizados, el checksum es el mismo, como también podemos ver, el Fortigate01 está actuando como primario y el Fortigate02 como secundario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="619" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13-1536x497.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13293" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?fit=1914%2C619&amp;ssl=1" data-orig-size="1914,619" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?fit=640%2C207&amp;ssl=1" class="aligncenter size-full wp-image-13293" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?resize=640%2C207&#038;ssl=1" alt="" width="640" height="207" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?resize=595%2C192&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?resize=960%2C310&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?resize=768%2C248&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?resize=1536%2C497&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_13.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para ver de un solo vistazo el estado de nuestro Cluster HA, vamos a habilitar el siguiente panel, nos vamos a Dashboard y añadir:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_14.png?ssl=1" data-lbwps-width="498" data-lbwps-height="469" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13294" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_14.png?fit=498%2C469&amp;ssl=1" data-orig-size="498,469" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_14.png?fit=498%2C469&amp;ssl=1" class="aligncenter size-full wp-image-13294" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_14.png?resize=498%2C469&#038;ssl=1" alt="" width="498" height="469" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?ssl=1" data-lbwps-width="1602" data-lbwps-height="279" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15-1536x268.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13295" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?fit=1602%2C279&amp;ssl=1" data-orig-size="1602,279" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?fit=640%2C111&amp;ssl=1" class="aligncenter size-full wp-image-13295" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?resize=640%2C111&#038;ssl=1" alt="" width="640" height="111" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?w=1602&amp;ssl=1 1602w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?resize=595%2C104&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?resize=960%2C167&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?resize=768%2C134&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?resize=1536%2C268&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_15.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Añadimos el Widget <strong>HA Status</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?ssl=1" data-lbwps-width="1886" data-lbwps-height="932" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16-1536x759.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13296" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?fit=1886%2C932&amp;ssl=1" data-orig-size="1886,932" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?fit=640%2C316&amp;ssl=1" class="aligncenter size-full wp-image-13296" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?resize=640%2C316&#038;ssl=1" alt="" width="640" height="316" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?w=1886&amp;ssl=1 1886w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?resize=595%2C294&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?resize=960%2C474&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?resize=768%2C380&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?resize=1536%2C759&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_16.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?ssl=1" data-lbwps-width="1565" data-lbwps-height="275" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17-1536x270.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13297" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?fit=1565%2C275&amp;ssl=1" data-orig-size="1565,275" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?fit=640%2C113&amp;ssl=1" class="aligncenter size-full wp-image-13297" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?resize=640%2C112&#038;ssl=1" alt="" width="640" height="112" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?w=1565&amp;ssl=1 1565w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?resize=595%2C105&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?resize=960%2C169&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?resize=768%2C135&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?resize=1536%2C270&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_17.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, de un solo vistazo podemos ver el estado del cluster HA:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_18.png?ssl=1" data-lbwps-width="700" data-lbwps-height="478" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13298" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_18.png?fit=700%2C478&amp;ssl=1" data-orig-size="700,478" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_18.png?fit=640%2C437&amp;ssl=1" class="aligncenter size-full wp-image-13298" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_18.png?resize=640%2C437&#038;ssl=1" alt="" width="640" height="437" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_18.png?w=700&amp;ssl=1 700w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_18.png?resize=595%2C406&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a realizar una prueba, apagando el Fortigate01, para ver si el Fortigate02 coge el control como primario, y como podemos ver, todo funciona correctamente sin pérdida de servicio y el que estaba antes como secundario pasa a ser primario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?ssl=1" data-lbwps-width="1908" data-lbwps-height="438" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19-1536x353.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13299" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?fit=1908%2C438&amp;ssl=1" data-orig-size="1908,438" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?fit=640%2C147&amp;ssl=1" class="aligncenter size-full wp-image-13299" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?resize=640%2C147&#038;ssl=1" alt="" width="640" height="147" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?w=1908&amp;ssl=1 1908w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?resize=595%2C137&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?resize=960%2C220&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?resize=768%2C176&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?resize=1536%2C353&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_19.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si volvemos a iniciar el Fortigate01, podemos ver que ahora tiene el rol de secundario, ya que el Uptime del Fortigate02 es mayor que el del Fortigate01:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?ssl=1" data-lbwps-width="1902" data-lbwps-height="405" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20-1536x327.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13300" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?fit=1902%2C405&amp;ssl=1" data-orig-size="1902,405" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?fit=640%2C136&amp;ssl=1" class="aligncenter size-full wp-image-13300" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?resize=640%2C136&#038;ssl=1" alt="" width="640" height="136" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?w=1902&amp;ssl=1 1902w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?resize=595%2C127&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?resize=960%2C204&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?resize=768%2C164&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?resize=1536%2C327&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_20.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_21.png?ssl=1" data-lbwps-width="649" data-lbwps-height="427" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13301" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_21.png?fit=649%2C427&amp;ssl=1" data-orig-size="649,427" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_21.png?fit=640%2C421&amp;ssl=1" class="aligncenter size-full wp-image-13301" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_21.png?resize=640%2C421&#038;ssl=1" alt="" width="640" height="421" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_21.png?w=649&amp;ssl=1 649w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_21.png?resize=595%2C391&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si queremos que el Fortigate01 vuelva a coger el rol de primario, debemos de ejecutar este comando <strong>diagnose sys ha reset-uptime,</strong> lo que hace este comando es resetear el Uptime del dispositivo, en este caso del Fortigate02:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_22.png?ssl=1" data-lbwps-width="894" data-lbwps-height="246" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_22.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13302" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_22.png?fit=894%2C246&amp;ssl=1" data-orig-size="894,246" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_22.png?fit=640%2C176&amp;ssl=1" class="aligncenter size-full wp-image-13302" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_22.png?resize=640%2C176&#038;ssl=1" alt="" width="640" height="176" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_22.png?w=894&amp;ssl=1 894w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_22.png?resize=595%2C164&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_22.png?resize=768%2C211&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, el Fortigate01 vuelve a tener el rol de primario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?ssl=1" data-lbwps-width="1909" data-lbwps-height="391" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23-1536x315.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13303" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?fit=1909%2C391&amp;ssl=1" data-orig-size="1909,391" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?fit=640%2C131&amp;ssl=1" class="aligncenter size-full wp-image-13303" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?resize=640%2C131&#038;ssl=1" alt="" width="640" height="131" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?w=1909&amp;ssl=1 1909w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?resize=595%2C122&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?resize=960%2C197&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?resize=768%2C157&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?resize=1536%2C315&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_23.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_24.png?ssl=1" data-lbwps-width="639" data-lbwps-height="423" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_24.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13304" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_24.png?fit=639%2C423&amp;ssl=1" data-orig-size="639,423" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_24.png?fit=639%2C423&amp;ssl=1" class="aligncenter size-full wp-image-13304" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_24.png?resize=639%2C423&#038;ssl=1" alt="" width="639" height="423" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_24.png?w=639&amp;ssl=1 639w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_24.png?resize=595%2C394&amp;ssl=1 595w" sizes="auto, (max-width: 639px) 100vw, 639px" /></a></p>
<ul>
<li>Ahora, vamos a configurar el Monitor interfaces en el cluster HA, esto significa, que la interface que vamos a monitorizar, si pierde conexión con el Firewall primario, automáticamente éste Firewall pasará a ser el secundario, tomando el otro Firewall el control, por lo tanto, vamos a configurar como Monitor interface, nuestra LAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png?ssl=1" data-lbwps-width="1248" data-lbwps-height="735" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13305" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png?fit=1248%2C735&amp;ssl=1" data-orig-size="1248,735" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png?fit=640%2C377&amp;ssl=1" class="aligncenter size-full wp-image-13305" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png?resize=640%2C377&#038;ssl=1" alt="" width="640" height="377" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png?w=1248&amp;ssl=1 1248w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png?resize=595%2C350&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png?resize=960%2C565&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_25.png?resize=768%2C452&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para terminar, vamos a ver como configurar las interfaces de management de cada Fortigate, ya que siempre que accedemos lo estamos haciendo sobre el dispositivo que tiene el rol de primario, estas interfaces de management nos van a permitir acceder a cada dispositivo por separado, para ello, accedemos a <strong>System &gt; HA </strong>seleccionamos el Fortigate con el rol de <strong>primario</strong> y <strong>Edit:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="434" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26-1536x348.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13306" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_26#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?fit=1914%2C434&amp;ssl=1" data-orig-size="1914,434" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_26" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?fit=640%2C145&amp;ssl=1" class="aligncenter size-full wp-image-13306" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?resize=640%2C145&#038;ssl=1" alt="" width="640" height="145" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?resize=595%2C135&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?resize=960%2C218&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?resize=768%2C174&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?resize=1536%2C348&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_26.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Habilitamos <strong>Management Interface Reservation</strong>, le indicamos el puerto, el gateway y la subred, al habilitar esta opción le estamos indicando al cluster que vamso a usar el puerto 9 de cada Fortigate para management y por lo tanto las configuraciones en este puerto no se van a sincronizar entre los dispositivos pertenecientes al cluster:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png?ssl=1" data-lbwps-width="1236" data-lbwps-height="828" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13321" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_39#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png?fit=1236%2C828&amp;ssl=1" data-orig-size="1236,828" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_39" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png?fit=640%2C429&amp;ssl=1" class="aligncenter size-full wp-image-13321" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png?resize=640%2C429&#038;ssl=1" alt="" width="640" height="429" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png?w=1236&amp;ssl=1 1236w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png?resize=595%2C399&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png?resize=960%2C643&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_39.png?resize=768%2C514&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Una vez habilitado el puerto de management en el cluster (puerto9), vamos a configurar este puerto sobre el Fortigate con el rol de primario, para ello, accedemos a <strong>Network &gt; Interfaces &gt; port9 &gt; Edit:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?ssl=1" data-lbwps-width="1898" data-lbwps-height="800" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28-1536x647.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13308" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_28#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?fit=1898%2C800&amp;ssl=1" data-orig-size="1898,800" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_28" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?fit=640%2C270&amp;ssl=1" class="aligncenter size-full wp-image-13308" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?resize=640%2C270&#038;ssl=1" alt="" width="640" height="270" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?w=1898&amp;ssl=1 1898w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?resize=595%2C251&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?resize=960%2C405&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?resize=768%2C324&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?resize=1536%2C647&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_28.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Le indicamos un Alias, le asignamos el direccionamiento IP correspondiente, habilitamos los accesos y OK:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png?ssl=1" data-lbwps-width="1240" data-lbwps-height="951" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13309" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_29#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png?fit=1240%2C951&amp;ssl=1" data-orig-size="1240,951" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_29" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png?fit=640%2C491&amp;ssl=1" class="aligncenter size-full wp-image-13309" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png?resize=640%2C491&#038;ssl=1" alt="" width="640" height="491" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png?w=1240&amp;ssl=1 1240w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png?resize=595%2C456&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png?resize=960%2C736&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_29.png?resize=768%2C589&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver ya tenemos configurado el puerto de management sobre el Fortigate primario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?ssl=1" data-lbwps-width="1354" data-lbwps-height="585" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13310" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_30#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?fit=1354%2C585&amp;ssl=1" data-orig-size="1354,585" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_30" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?fit=640%2C277&amp;ssl=1" class="aligncenter size-full wp-image-13310" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?resize=640%2C277&#038;ssl=1" alt="" width="640" height="277" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?w=1354&amp;ssl=1 1354w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?resize=595%2C257&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?resize=960%2C415&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?resize=768%2C332&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_30.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora ya podemos acceder a través de la IP de management sobre el Fortigate01:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?ssl=1" data-lbwps-width="1913" data-lbwps-height="726" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31-1536x583.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13311" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_31#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?fit=1913%2C726&amp;ssl=1" data-orig-size="1913,726" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_31" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?fit=640%2C243&amp;ssl=1" class="aligncenter size-full wp-image-13311" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?resize=640%2C243&#038;ssl=1" alt="" width="640" height="243" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?w=1913&amp;ssl=1 1913w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?resize=595%2C226&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?resize=960%2C364&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?resize=768%2C291&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?resize=1536%2C583&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_31.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a configurar la interface de management del Fortigate que tiene el rol de secundario, para ello desde la consola web nos abrimos una consola CLI:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?ssl=1" data-lbwps-width="1910" data-lbwps-height="348" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32-1536x280.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13312" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_32#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?fit=1910%2C348&amp;ssl=1" data-orig-size="1910,348" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_32" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?fit=640%2C117&amp;ssl=1" class="aligncenter size-full wp-image-13312" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?resize=640%2C117&#038;ssl=1" alt="" width="640" height="117" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?w=1910&amp;ssl=1 1910w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?resize=595%2C108&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?resize=960%2C175&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?resize=768%2C140&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?resize=1536%2C280&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_32.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ejecutamos el comando <strong>execute ha manage ?</strong> y cómo podemos ver nos indica que el dispositivo 0 es el secundario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_33.png?ssl=1" data-lbwps-width="656" data-lbwps-height="242" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_33.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13313" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_33#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_33.png?fit=656%2C242&amp;ssl=1" data-orig-size="656,242" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_33" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_33.png?fit=640%2C236&amp;ssl=1" class="aligncenter size-full wp-image-13313" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_33.png?resize=640%2C236&#038;ssl=1" alt="" width="640" height="236" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_33.png?w=656&amp;ssl=1 656w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_33.png?resize=595%2C219&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Por lo tanto, para acceder al Fortigate secundario debemos de ejecutar el comando <strong>execute ha manage 0 admin</strong> el admin es el usuario que tenemos dado de alta en nuestro Fortigate secundario con permisos administrativos, y cómo podemos ver ya estamos dentro del Fortigate secundario (FORTIGATE02):</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_34.png?ssl=1" data-lbwps-width="882" data-lbwps-height="317" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_34.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13314" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_34#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_34.png?fit=882%2C317&amp;ssl=1" data-orig-size="882,317" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_34" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_34.png?fit=640%2C230&amp;ssl=1" class="aligncenter size-full wp-image-13314" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_34.png?resize=640%2C230&#038;ssl=1" alt="" width="640" height="230" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_34.png?w=882&amp;ssl=1 882w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_34.png?resize=595%2C214&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_34.png?resize=768%2C276&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora ya le podemos asignar el direccionamiento IP al puerto que configuramos para management (puerto9), con el comando <strong>config system interface </strong>accedemos al modo de configuración de interface, con <strong>edit port9 </strong>accedemos a la configuración del puerto 9, con <strong>set ip 192.168.99.221 255.255.255.0</strong> le asignamos el direccionamiento IP, con <strong>set allowaccess ping https http ssh fgfm </strong>le habilitamos los accesos y con <strong>end</strong> salimos de las configuraciones:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_35.png?ssl=1" data-lbwps-width="873" data-lbwps-height="485" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_35.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13315" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_35#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_35.png?fit=873%2C485&amp;ssl=1" data-orig-size="873,485" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_35" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_35.png?fit=640%2C356&amp;ssl=1" class="aligncenter size-full wp-image-13315" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_35.png?resize=640%2C356&#038;ssl=1" alt="" width="640" height="356" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_35.png?w=873&amp;ssl=1 873w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_35.png?resize=595%2C331&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_35.png?resize=768%2C427&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con el comando <strong>show system interface</strong> podemos ver las configuraciones realizadas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_36.png?ssl=1" data-lbwps-width="783" data-lbwps-height="499" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_36.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13316" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_36#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_36.png?fit=783%2C499&amp;ssl=1" data-orig-size="783,499" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_36" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_36.png?fit=640%2C408&amp;ssl=1" class="aligncenter size-full wp-image-13316" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_36.png?resize=640%2C408&#038;ssl=1" alt="" width="640" height="408" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_36.png?w=783&amp;ssl=1 783w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_36.png?resize=595%2C379&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_36.png?resize=768%2C489&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_37.png?ssl=1" data-lbwps-width="801" data-lbwps-height="698" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_37.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13317" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_37#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_37.png?fit=801%2C698&amp;ssl=1" data-orig-size="801,698" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_37" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_37.png?fit=640%2C558&amp;ssl=1" class="aligncenter size-full wp-image-13317" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_37.png?resize=640%2C558&#038;ssl=1" alt="" width="640" height="558" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_37.png?w=801&amp;ssl=1 801w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_37.png?resize=595%2C518&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_37.png?resize=768%2C669&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora ya podemos acceder a través de la IP de management sobre el Fortigate02, y cómo podemos ver ya tenemos el puerto de management configurado (puerto9):</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?ssl=1" data-lbwps-width="1898" data-lbwps-height="952" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38-1536x770.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13318" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-activo/fhaaa_38#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?fit=1898%2C952&amp;ssl=1" data-orig-size="1898,952" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaaa_38" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?fit=640%2C321&amp;ssl=1" class="aligncenter size-full wp-image-13318" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?resize=640%2C321&#038;ssl=1" alt="" width="640" height="321" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?w=1898&amp;ssl=1 1898w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?resize=595%2C298&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?resize=960%2C482&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?resize=768%2C385&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?resize=1536%2C770&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaaa_38.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/fortigate-ha-activo-activo/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13280</post-id>	</item>
		<item>
		<title>Fortigate HA ACTIVO &#8211; PASIVO</title>
		<link>https://blog.ragasys.es/fortigate-ha-activo-pasivo</link>
					<comments>https://blog.ragasys.es/fortigate-ha-activo-pasivo#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Tue, 20 Apr 2021 07:47:18 +0000</pubDate>
				<category><![CDATA[Cluster]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[HA]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Routing]]></category>
		<category><![CDATA[Switching]]></category>
		<category><![CDATA[TIC]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=13249</guid>

					<description><![CDATA[Hola a tod@s, En este post vamos a ver como configurar dos Firewall Fortigate en HA (Alta Disponibilidad) en modo Activo-Pasivo: Vamos a utilizar dos Interfaces de cada dispositivo para HA para vincularlos y sincronizarlos. En HA uno de los&#8230; <a href="https://blog.ragasys.es/fortigate-ha-activo-pasivo" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s,</p>
<p>En este post vamos a ver como configurar dos Firewall Fortigate en HA (Alta Disponibilidad) en modo Activo-Pasivo:</p>
<ul>
<li>Vamos a utilizar dos Interfaces de cada dispositivo para HA para vincularlos y sincronizarlos.</li>
<li>En HA uno de los Fortigate estará como primario y éste sincronizará su información con el otro Fortigate que será el secundario.</li>
<li>El link para el HA entre los Fortigate, que en este caso usaremos dos (HA1 y HA2) se llama Heartbeat y se utiliza para la sincronización y detección entre los equipos.</li>
<li>Tenemos dos modos de configurar HA: Activo-Pasivo y Activo-Activo.</li>
</ul>
<p>En este primer post vamos a ver el modo Activo-Pasivo, en este modo solo el dispositivo primario procesa el tráfico, el otro dispositivo está en modo de espera y sólo entrará a funcionar en caso de caída del primario, toda la configuración realizada en el dispositivo primario se sincronizará con el dispositivo secundario.</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png?ssl=1" data-lbwps-width="1152" data-lbwps-height="442" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13250" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png?fit=1152%2C442&amp;ssl=1" data-orig-size="1152,442" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png?fit=640%2C245&amp;ssl=1" class="aligncenter size-full wp-image-13250" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png?resize=640%2C246&#038;ssl=1" alt="" width="640" height="246" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png?w=1152&amp;ssl=1 1152w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png?resize=595%2C228&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png?resize=960%2C368&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_1.png?resize=768%2C295&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>Vamos a ver que necesitamos para crear y configurar un cluster HA en Firewall FortiGates:</p>
<ul>
<li>Dos Fortigates del mismo modelo</li>
<li>Misma versión de FortiOS en ambos equipos</li>
<li>Mismas licencias</li>
<li>Un link entre los equipos que componen el cluster HA, en este caso vamos a utilizar dos</li>
<li>Las mismas interfaces deben de estar conectadas al mismo dominio de broadcast, es decir, los puertos usados deben de ser los mismos en ambos dispositivos y conectados en el mismo segmento de red.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li>Para empezar con la configuración de nuestro cluster HA Activo-Pasivo, vamos a realizar las configuraciones básicas sobre uno de nuestros Fortigate, que actuará como primario, el otro Fortigate lo dejamos con las configuraciones de fábrica, <a href="https://blog.ragasys.es/fortigate-configuracion-inicial-y-puesta-en-marcha" target="_blank" rel="noopener">en este link podemos ver la configuración inicial y puesta en marcha</a>.</li>
<li>Aquí vemos como tenemos configurado el hostname y las interfaces de red del primer Fortigate (LAN y WAN):</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_2.png?ssl=1" data-lbwps-width="737" data-lbwps-height="438" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13251" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_2.png?fit=737%2C438&amp;ssl=1" data-orig-size="737,438" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_2.png?fit=640%2C380&amp;ssl=1" class="aligncenter size-full wp-image-13251" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_2.png?resize=640%2C380&#038;ssl=1" alt="" width="640" height="380" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_2.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_2.png?resize=595%2C354&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_3.png?ssl=1" data-lbwps-width="736" data-lbwps-height="416" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13252" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_3.png?fit=736%2C416&amp;ssl=1" data-orig-size="736,416" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_3.png?fit=640%2C362&amp;ssl=1" class="aligncenter size-full wp-image-13252" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_3.png?resize=640%2C362&#038;ssl=1" alt="" width="640" height="362" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_3.png?w=736&amp;ssl=1 736w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_3.png?resize=595%2C336&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Del segundo Fortigate, está tal y como viene de fábrica:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_4.png?ssl=1" data-lbwps-width="735" data-lbwps-height="295" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13253" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_4.png?fit=735%2C295&amp;ssl=1" data-orig-size="735,295" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_4.png?fit=640%2C257&amp;ssl=1" class="aligncenter size-full wp-image-13253" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_4.png?resize=640%2C257&#038;ssl=1" alt="" width="640" height="257" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_4.png?w=735&amp;ssl=1 735w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_4.png?resize=595%2C239&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo primero que vamos a realizar es configurar sobre el Fortigate01 el nombre de las interfaces de red que van a participar en el cluster HA, se llaman interfaces de Heartbeat y se utilizan para la sincronización y detección entre los equipos, utilizaremos los puertos 4 y 5:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_5.png?ssl=1" data-lbwps-width="737" data-lbwps-height="411" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13254" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_5.png?fit=737%2C411&amp;ssl=1" data-orig-size="737,411" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_5.png?fit=640%2C357&amp;ssl=1" class="aligncenter size-full wp-image-13254" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_5.png?resize=640%2C357&#038;ssl=1" alt="" width="640" height="357" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_5.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_5.png?resize=595%2C332&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora sobre <strong>System &gt; HA &gt; </strong>seleccionamos el modo que nos interese, en este caso<strong> Active-Passive:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_6.png?ssl=1" data-lbwps-width="736" data-lbwps-height="412" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13255" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_6.png?fit=736%2C412&amp;ssl=1" data-orig-size="736,412" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_6.png?fit=640%2C358&amp;ssl=1" class="aligncenter size-full wp-image-13255" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_6.png?resize=640%2C358&#038;ssl=1" alt="" width="640" height="358" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_6.png?w=736&amp;ssl=1 736w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_6.png?resize=595%2C333&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre <strong>High Availability </strong>le indicamos el modo y la prioridad, sobre <strong>Cluster Settings </strong>le damos un nombre al cluster, le asignamos un password, habilitamos <strong>Session pickup</strong> para que automáticamente se pasen las sesiones de un Fortigate a otro y así los clientes no tengan que volver a reconectarse, el <strong>Monitor interfaces</strong> lo vamos a habilitar más adelante y explicaremos de que se trata y sobre <strong>Heartbeat Interfaces</strong> vamos a configurar las interfaces que van a participar en el cluster HA, sobre <strong>Heartbeat Interface Priority </strong>vamos a configurar las prioridades de las interfaces de Heartbeat, que en este caso el port4 va a tener prioridad sobre el port5:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_7.png?ssl=1" data-lbwps-width="736" data-lbwps-height="431" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13256" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_7.png?fit=736%2C431&amp;ssl=1" data-orig-size="736,431" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_7.png?fit=640%2C375&amp;ssl=1" class="aligncenter size-full wp-image-13256" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_7.png?resize=640%2C375&#038;ssl=1" alt="" width="640" height="375" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_7.png?w=736&amp;ssl=1 736w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_7.png?resize=595%2C348&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora podemos ver que en <strong>System &gt; HA</strong> nos muestra los puertos 4 y 5 con un corazón indicando que son los puertos de Heartbeat para el cluster:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_8.png?ssl=1" data-lbwps-width="737" data-lbwps-height="243" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13257" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_8.png?fit=737%2C243&amp;ssl=1" data-orig-size="737,243" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_8.png?fit=640%2C211&amp;ssl=1" class="aligncenter size-full wp-image-13257" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_8.png?resize=640%2C211&#038;ssl=1" alt="" width="640" height="211" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_8.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_8.png?resize=595%2C196&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre el Fortigate01 ya tenemos las configuraciones de HA realizadas, ahora debemos de configurar el Fortigate02, y como el nombre del host no se sincroniza, es lo primero que tenemos que configurar, en <strong>System &gt; Settings</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_9.png?ssl=1" data-lbwps-width="737" data-lbwps-height="542" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13258" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_9.png?fit=737%2C542&amp;ssl=1" data-orig-size="737,542" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_9.png?fit=640%2C471&amp;ssl=1" class="aligncenter size-full wp-image-13258" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_9.png?resize=640%2C471&#038;ssl=1" alt="" width="640" height="471" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_9.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_9.png?resize=595%2C438&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora sobre <strong>System &gt; HA</strong> realizamos las mismas configuraciones que hemos hecho sobre el Fortigate01, excepto que en la prioridad del dispositivo la vamos a bajar a 100, clic sobre OK:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_10.png?ssl=1" data-lbwps-width="737" data-lbwps-height="424" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13259" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_10.png?fit=737%2C424&amp;ssl=1" data-orig-size="737,424" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_10.png?fit=640%2C368&amp;ssl=1" class="aligncenter size-full wp-image-13259" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_10.png?resize=640%2C368&#038;ssl=1" alt="" width="640" height="368" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_10.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_10.png?resize=595%2C342&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver perdemos conexión con nuestro Fortigate02, ya que la dirección IP que tenía, ha desaparecido al unirlo al cluster, ahora estos dos dispositivos es como si fuesen uno solo y los dos van a tener las mismas configuraciones:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_11.png?ssl=1" data-lbwps-width="737" data-lbwps-height="399" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13260" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_11.png?fit=737%2C399&amp;ssl=1" data-orig-size="737,399" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_11.png?fit=640%2C346&amp;ssl=1" class="aligncenter size-full wp-image-13260" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_11.png?resize=640%2C346&#038;ssl=1" alt="" width="640" height="346" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_11.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_11.png?resize=595%2C322&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre el Fortigate01 accedemos a <strong>System &gt; HA </strong>y podemos ver que ya tenemos el segundo dispositivo unido al cluster, aunque todavía está sincronizando, esto nos lo muestra muy claro el checksum, que como podemos observar son números diferentes, ya que al no estar sincronizados todavía cada dispositivo tiene una configuración:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_12.png?ssl=1" data-lbwps-width="735" data-lbwps-height="239" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13261" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_12.png?fit=735%2C239&amp;ssl=1" data-orig-size="735,239" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_12.png?fit=640%2C208&amp;ssl=1" class="aligncenter size-full wp-image-13261" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_12.png?resize=640%2C208&#038;ssl=1" alt="" width="640" height="208" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_12.png?w=735&amp;ssl=1 735w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_12.png?resize=595%2C193&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Pasados unos minutos, ya podemos ver que los dos dispositivos están sincronizados, el checksum es el mismo, como también podemos ver, el Fortigate01 está actuando como primario y el Fortigate02 como secundario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_13.png?ssl=1" data-lbwps-width="737" data-lbwps-height="245" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13262" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_13.png?fit=737%2C245&amp;ssl=1" data-orig-size="737,245" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_13.png?fit=640%2C213&amp;ssl=1" class="aligncenter size-full wp-image-13262" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_13.png?resize=640%2C213&#038;ssl=1" alt="" width="640" height="213" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_13.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_13.png?resize=595%2C198&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para ver de un solo vistazo el estado de nuestro Cluster HA, vamos a habilitar el siguiente panel, nos vamos a Dashboard y añadir:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_14.png?ssl=1" data-lbwps-width="498" data-lbwps-height="469" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13263" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_14.png?fit=498%2C469&amp;ssl=1" data-orig-size="498,469" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_14.png?fit=498%2C469&amp;ssl=1" class="aligncenter size-full wp-image-13263" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_14.png?resize=498%2C469&#038;ssl=1" alt="" width="498" height="469" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_15.png?ssl=1" data-lbwps-width="737" data-lbwps-height="129" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13264" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_15.png?fit=737%2C129&amp;ssl=1" data-orig-size="737,129" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_15.png?fit=640%2C112&amp;ssl=1" class="aligncenter size-full wp-image-13264" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_15.png?resize=640%2C112&#038;ssl=1" alt="" width="640" height="112" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_15.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_15.png?resize=595%2C104&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Añadimos el Widget <strong>HA Status</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_16.png?ssl=1" data-lbwps-width="735" data-lbwps-height="363" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13265" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_16.png?fit=735%2C363&amp;ssl=1" data-orig-size="735,363" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_16.png?fit=640%2C316&amp;ssl=1" class="aligncenter size-full wp-image-13265" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_16.png?resize=640%2C316&#038;ssl=1" alt="" width="640" height="316" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_16.png?w=735&amp;ssl=1 735w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_16.png?resize=595%2C294&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_17.png?ssl=1" data-lbwps-width="737" data-lbwps-height="129" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13266" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_17.png?fit=737%2C129&amp;ssl=1" data-orig-size="737,129" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_17.png?fit=640%2C112&amp;ssl=1" class="aligncenter size-full wp-image-13266" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_17.png?resize=640%2C112&#038;ssl=1" alt="" width="640" height="112" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_17.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_17.png?resize=595%2C104&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, de un solo vistazo podemos ver el estado del cluster HA:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_18.png?ssl=1" data-lbwps-width="737" data-lbwps-height="472" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13267" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_18.png?fit=737%2C472&amp;ssl=1" data-orig-size="737,472" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_18.png?fit=640%2C410&amp;ssl=1" class="aligncenter size-full wp-image-13267" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_18.png?resize=640%2C410&#038;ssl=1" alt="" width="640" height="410" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_18.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_18.png?resize=595%2C381&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a realizar una prueba, apagando el Fortigate01, para ver si el Fortigate02 coge el control como primario, y como podemos ver, todo funciona correctamente sin pérdida de servicio y el que estaba antes como secundario pasa a ser primario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_19.png?ssl=1" data-lbwps-width="735" data-lbwps-height="164" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13268" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_19.png?fit=735%2C164&amp;ssl=1" data-orig-size="735,164" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_19.png?fit=640%2C143&amp;ssl=1" class="aligncenter size-full wp-image-13268" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_19.png?resize=640%2C143&#038;ssl=1" alt="" width="640" height="143" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_19.png?w=735&amp;ssl=1 735w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_19.png?resize=595%2C133&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si volvemos a iniciar el Fortigate01, podemos ver que ahora tiene el rol de secundario, ya que el Uptime del Fortigate02 es mayor que el del Fortigate01:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_20.png?ssl=1" data-lbwps-width="735" data-lbwps-height="157" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13269" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_20.png?fit=735%2C157&amp;ssl=1" data-orig-size="735,157" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_20.png?fit=640%2C137&amp;ssl=1" class="aligncenter size-full wp-image-13269" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_20.png?resize=640%2C137&#038;ssl=1" alt="" width="640" height="137" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_20.png?w=735&amp;ssl=1 735w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_20.png?resize=595%2C127&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_21.png?ssl=1" data-lbwps-width="737" data-lbwps-height="421" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13270" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_21.png?fit=737%2C421&amp;ssl=1" data-orig-size="737,421" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_21.png?fit=640%2C366&amp;ssl=1" class="aligncenter size-full wp-image-13270" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_21.png?resize=640%2C366&#038;ssl=1" alt="" width="640" height="366" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_21.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_21.png?resize=595%2C340&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si queremos que el Fortigate01 vuelva a coger el rol de primario, debemos de ejecutar este comando <strong>diagnose sys ha reset-uptime,</strong> lo que hace este comando es resetear el Uptime del dispositivo, en este caso del Fortigate02:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_22.png?ssl=1" data-lbwps-width="737" data-lbwps-height="203" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_22.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13271" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_22.png?fit=737%2C203&amp;ssl=1" data-orig-size="737,203" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_22.png?fit=640%2C176&amp;ssl=1" class="aligncenter size-full wp-image-13271" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_22.png?resize=640%2C176&#038;ssl=1" alt="" width="640" height="176" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_22.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_22.png?resize=595%2C164&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, el Fortigate01 vuelve a tener el rol de primario:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_23.png?ssl=1" data-lbwps-width="735" data-lbwps-height="145" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_23.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13272" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_23.png?fit=735%2C145&amp;ssl=1" data-orig-size="735,145" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_23.png?fit=640%2C126&amp;ssl=1" class="aligncenter size-full wp-image-13272" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_23.png?resize=640%2C126&#038;ssl=1" alt="" width="640" height="126" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_23.png?w=735&amp;ssl=1 735w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_23.png?resize=595%2C117&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_24.png?ssl=1" data-lbwps-width="672" data-lbwps-height="448" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_24.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13273" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_24.png?fit=672%2C448&amp;ssl=1" data-orig-size="672,448" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_24.png?fit=640%2C427&amp;ssl=1" class="aligncenter size-full wp-image-13273" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_24.png?resize=640%2C427&#038;ssl=1" alt="" width="640" height="427" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_24.png?w=672&amp;ssl=1 672w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_24.png?resize=595%2C397&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para terminar, vamos a configurar el Monitor interfaces en el cluster HA, esto significa, que la interface que vamos a monitorizar, si pierde conexión con el Firewall primario, automáticamente éste Firewall pasará a ser el secundario, tomando el otro Firewall el control, por lo tanto, vamos a configurar como Monitor interface, nuestra LAN:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_25.png?ssl=1" data-lbwps-width="737" data-lbwps-height="431" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2021/04/fhaap_25.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="13274" data-permalink="https://blog.ragasys.es/fortigate-ha-activo-pasivo/fhaap_25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_25.png?fit=737%2C431&amp;ssl=1" data-orig-size="737,431" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fhaap_25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_25.png?fit=640%2C374&amp;ssl=1" class="aligncenter size-full wp-image-13274" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_25.png?resize=640%2C374&#038;ssl=1" alt="" width="640" height="374" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_25.png?w=737&amp;ssl=1 737w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2021/04/fhaap_25.png?resize=595%2C348&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/fortigate-ha-activo-pasivo/feed</wfw:commentRss>
			<slash:comments>8</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13249</post-id>	</item>
		<item>
		<title>Fortigate SSL VPN con segundo factor de autenticación usando cuenta de email</title>
		<link>https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email</link>
					<comments>https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Wed, 20 Jan 2021 08:25:48 +0000</pubDate>
				<category><![CDATA[Accesos remotos]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Forticlient]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[FortiToken]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[VPN]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=12685</guid>

					<description><![CDATA[Hola a tod@s. En este post vamos a ver como autenticarnos a una VPN SSL con un segundo factor de autenticación usando una cuenta de correo electrónico. Accedemos a nuestro firewall Fortigate, y nos situamos sobre Usuario y Dispositivo &#62;&#8230; <a href="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s.</p>
<p>En este post vamos a ver como autenticarnos a una VPN SSL con un segundo factor de autenticación usando una cuenta de correo electrónico.</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_1.png?ssl=1" data-lbwps-width="736" data-lbwps-height="397" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12686" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_1.png?fit=736%2C397&amp;ssl=1" data-orig-size="736,397" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_1.png?fit=640%2C345&amp;ssl=1" class="aligncenter size-full wp-image-12686" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_1.png?resize=640%2C345&#038;ssl=1" alt="" width="640" height="345" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_1.png?w=736&amp;ssl=1 736w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_1.png?resize=595%2C321&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Accedemos a nuestro firewall Fortigate, y nos situamos sobre <strong>Usuario y Dispositivo &gt; Definición de Usuario</strong>, como podemos ver tenemos el usuario local joseramon.ramos, si lo editamos vemos que pertenece al grupo que tiene acceso a la VPN SSL:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?ssl=1" data-lbwps-width="1664" data-lbwps-height="442" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2-1536x408.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12687" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?fit=1664%2C442&amp;ssl=1" data-orig-size="1664,442" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?fit=640%2C170&amp;ssl=1" class="aligncenter size-full wp-image-12687" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?resize=640%2C170&#038;ssl=1" alt="" width="640" height="170" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?w=1664&amp;ssl=1 1664w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?resize=595%2C158&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?resize=960%2C255&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?resize=768%2C204&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?resize=1536%2C408&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_2.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png?ssl=1" data-lbwps-width="1258" data-lbwps-height="719" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12688" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png?fit=1258%2C719&amp;ssl=1" data-orig-size="1258,719" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png?fit=640%2C366&amp;ssl=1" class="aligncenter size-full wp-image-12688" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png?resize=640%2C366&#038;ssl=1" alt="" width="640" height="366" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png?w=1258&amp;ssl=1 1258w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png?resize=595%2C340&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png?resize=960%2C549&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_3.png?resize=768%2C439&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Vamos a realizar una prueba de conexión a la VPN SSL, para verificar que este usuario puede acceder:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_4.png?ssl=1" data-lbwps-width="882" data-lbwps-height="706" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12689" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_4.png?fit=882%2C706&amp;ssl=1" data-orig-size="882,706" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_4.png?fit=640%2C512&amp;ssl=1" class="aligncenter size-full wp-image-12689" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_4.png?resize=640%2C512&#038;ssl=1" alt="" width="640" height="512" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_4.png?w=882&amp;ssl=1 882w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_4.png?resize=595%2C476&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_4.png?resize=768%2C615&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_5.png?ssl=1" data-lbwps-width="877" data-lbwps-height="566" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12690" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_5.png?fit=877%2C566&amp;ssl=1" data-orig-size="877,566" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_5.png?fit=640%2C413&amp;ssl=1" class="aligncenter size-full wp-image-12690" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_5.png?resize=640%2C413&#038;ssl=1" alt="" width="640" height="413" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_5.png?w=877&amp;ssl=1 877w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_5.png?resize=595%2C384&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_5.png?resize=768%2C496&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos a <strong>Monitor &gt; Monitor SSL-VPN</strong>, podemos ver que el usuario está conectado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?ssl=1" data-lbwps-width="1723" data-lbwps-height="722" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6-1536x644.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12691" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?fit=1723%2C722&amp;ssl=1" data-orig-size="1723,722" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?fit=640%2C268&amp;ssl=1" class="aligncenter size-full wp-image-12691" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?resize=640%2C268&#038;ssl=1" alt="" width="640" height="268" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?w=1723&amp;ssl=1 1723w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?resize=595%2C249&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?resize=960%2C402&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?resize=768%2C322&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?resize=1536%2C644&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_6.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para configurar el segundo factor de autenticación por correo electrónico, lo primero que tenemos que hacer es configurar el servicio SMTP en nuestro Fortigate, para ello, accedemos a <strong>Sistema &gt; Configuración &gt; Email Service</strong> y configuramos nuestro servidor SMTP:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png?ssl=1" data-lbwps-width="1259" data-lbwps-height="792" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12692" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png?fit=1259%2C792&amp;ssl=1" data-orig-size="1259,792" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png?fit=640%2C403&amp;ssl=1" class="aligncenter size-full wp-image-12692" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png?resize=640%2C403&#038;ssl=1" alt="" width="640" height="403" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png?w=1259&amp;ssl=1 1259w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png?resize=595%2C374&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png?resize=960%2C604&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_7.png?resize=768%2C483&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos a la CLI y ejecutamos el comando <strong>config system email-server</strong>, también lo podemos configurar desde aquí, con <strong>get</strong> obtenemos la configuración realizada:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_8.png?ssl=1" data-lbwps-width="668" data-lbwps-height="460" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12693" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_8.png?fit=668%2C460&amp;ssl=1" data-orig-size="668,460" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_8.png?fit=640%2C441&amp;ssl=1" class="aligncenter size-full wp-image-12693" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_8.png?resize=640%2C441&#038;ssl=1" alt="" width="640" height="441" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_8.png?w=668&amp;ssl=1 668w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_8.png?resize=595%2C410&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>La otra configuración que tenemos que realizar para aplicar el segundo factor de autenticación a nuestros usuarios vpn es configurar un Fortitoken por email, pero como podemos ver, a través de la interfaz gráfica es imposible, ya que solo nos da las opciones de FortiToken Mobile y FortiToken Cloud, ambas opciones de pago, si lo configuramos por email no debemos de adquirir ninguna licencia:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png?ssl=1" data-lbwps-width="1232" data-lbwps-height="567" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12694" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png?fit=1232%2C567&amp;ssl=1" data-orig-size="1232,567" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png?fit=640%2C295&amp;ssl=1" class="aligncenter size-full wp-image-12694" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png?resize=640%2C295&#038;ssl=1" alt="" width="640" height="295" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png?w=1232&amp;ssl=1 1232w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png?resize=595%2C274&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png?resize=960%2C442&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_9.png?resize=768%2C353&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Pues bien, si accedemos, a la CLI podemos configurar el segundo factor de autenticación por correo electrónico, ejecutamos el comando <strong>config user local </strong>para acceder al modo de configuración de usuarios locales y ejecutando <strong>show </strong>nos mostrará la información de todos nuestros usuarios:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_10.png?ssl=1" data-lbwps-width="598" data-lbwps-height="836" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12695" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_10.png?fit=598%2C836&amp;ssl=1" data-orig-size="598,836" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_10.png?fit=598%2C836&amp;ssl=1" class="aligncenter size-full wp-image-12695" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_10.png?resize=598%2C836&#038;ssl=1" alt="" width="598" height="836" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_10.png?w=598&amp;ssl=1 598w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_10.png?resize=595%2C832&amp;ssl=1 595w" sizes="auto, (max-width: 598px) 100vw, 598px" /></a></p>
<ul>
<li>Editamos el usuario al que le vamos a configurar el segundo factor de autenticación por email, <strong>edit usuario</strong> y con <strong>get</strong> vemos toda la información:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_11.png?ssl=1" data-lbwps-width="595" data-lbwps-height="424" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12696" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_11.png?fit=595%2C424&amp;ssl=1" data-orig-size="595,424" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_11.png?fit=595%2C424&amp;ssl=1" class="aligncenter size-full wp-image-12696" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_11.png?resize=595%2C424&#038;ssl=1" alt="" width="595" height="424" /></a></p>
<ul>
<li>Si ejecutamos el comando <strong>set two-factor</strong> y pulsamos la tecla <strong>?</strong>, podemos ver las opciones de configuración del segundo factor de autenticación, mucho más completa que con la interfaz gráfica, ya que nos aparece la opción de poder configurar este segundo factor de autenticación por email:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_12.png?ssl=1" data-lbwps-width="596" data-lbwps-height="225" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12697" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_12.png?fit=596%2C225&amp;ssl=1" data-orig-size="596,225" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_12.png?fit=596%2C225&amp;ssl=1" class="aligncenter size-full wp-image-12697" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_12.png?resize=596%2C225&#038;ssl=1" alt="" width="596" height="225" /></a></p>
<ul>
<li>Con el comando <strong>set two-factor email</strong> habilitamos el segundo factor de autenticación vía correo electrónico:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_13.png?ssl=1" data-lbwps-width="591" data-lbwps-height="236" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12698" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_13.png?fit=591%2C236&amp;ssl=1" data-orig-size="591,236" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_13.png?fit=591%2C236&amp;ssl=1" class="aligncenter size-full wp-image-12698" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_13.png?resize=591%2C236&#038;ssl=1" alt="" width="591" height="236" /></a></p>
<ul>
<li>Ejecutando <strong>set email-to cuenta de email</strong>, le añadimos la cuenta de correo del usuario que será donde se reciban los token para autenticarse contra la VPN SSL:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_14.png?ssl=1" data-lbwps-width="595" data-lbwps-height="262" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12699" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_14.png?fit=595%2C262&amp;ssl=1" data-orig-size="595,262" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_14.png?fit=595%2C262&amp;ssl=1" class="aligncenter size-full wp-image-12699" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_14.png?resize=595%2C262&#038;ssl=1" alt="" width="595" height="262" /></a></p>
<ul>
<li>Si hacemos un <strong>get</strong> podemos ver que ya tenemos habilitado el segundo factor de autenticación por correo electrónico:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_15.png?ssl=1" data-lbwps-width="597" data-lbwps-height="563" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12700" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_15.png?fit=597%2C563&amp;ssl=1" data-orig-size="597,563" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_15.png?fit=597%2C563&amp;ssl=1" class="aligncenter size-full wp-image-12700" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_15.png?resize=597%2C563&#038;ssl=1" alt="" width="597" height="563" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_15.png?w=597&amp;ssl=1 597w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_15.png?resize=595%2C561&amp;ssl=1 595w" sizes="auto, (max-width: 597px) 100vw, 597px" /></a></p>
<ul>
<li>Ejecutamos <strong>end</strong> para finalizar y que se guarden los cambios:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_22.png?ssl=1" data-lbwps-width="594" data-lbwps-height="391" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_22.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12709" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_22.png?fit=594%2C391&amp;ssl=1" data-orig-size="594,391" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_22.png?fit=594%2C391&amp;ssl=1" class="aligncenter size-full wp-image-12709" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_22.png?resize=594%2C391&#038;ssl=1" alt="" width="594" height="391" /></a></p>
<ul>
<li>Si accedemos a la interfaz gráfica ya podemos ver las configuraciones que hemos realizado:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png?ssl=1" data-lbwps-width="1280" data-lbwps-height="723" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12701" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png?fit=1280%2C723&amp;ssl=1" data-orig-size="1280,723" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png?fit=640%2C361&amp;ssl=1" class="aligncenter size-full wp-image-12701" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png?resize=640%2C362&#038;ssl=1" alt="" width="640" height="362" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png?w=1280&amp;ssl=1 1280w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png?resize=595%2C336&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png?resize=960%2C542&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_16.png?resize=768%2C434&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a probar el acceso a nuestra VPN SSL con el usuario al que le hemos configurado el segundo factor de autenticación por email, para verificar que todo funciona correctamente, aquí vemos con nos pide el token que se ha enviado por mail:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_17.png?ssl=1" data-lbwps-width="882" data-lbwps-height="654" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12702" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_17.png?fit=882%2C654&amp;ssl=1" data-orig-size="882,654" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_17.png?fit=640%2C475&amp;ssl=1" class="aligncenter size-full wp-image-12702" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_17.png?resize=640%2C475&#038;ssl=1" alt="" width="640" height="475" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_17.png?w=882&amp;ssl=1 882w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_17.png?resize=595%2C441&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_17.png?resize=768%2C569&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos el token recibido por email:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?ssl=1" data-lbwps-width="1398" data-lbwps-height="393" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12703" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?fit=1398%2C393&amp;ssl=1" data-orig-size="1398,393" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?fit=640%2C180&amp;ssl=1" class="aligncenter size-full wp-image-12703" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?resize=640%2C180&#038;ssl=1" alt="" width="640" height="180" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?w=1398&amp;ssl=1 1398w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?resize=595%2C167&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?resize=960%2C270&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?resize=768%2C216&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_18.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Lo introducimos en nuestro Forticlient y Aceptamos:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_19.png?ssl=1" data-lbwps-width="887" data-lbwps-height="707" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12704" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_19.png?fit=887%2C707&amp;ssl=1" data-orig-size="887,707" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_19.png?fit=640%2C510&amp;ssl=1" class="aligncenter size-full wp-image-12704" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_19.png?resize=640%2C510&#038;ssl=1" alt="" width="640" height="510" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_19.png?w=887&amp;ssl=1 887w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_19.png?resize=595%2C474&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_19.png?resize=768%2C612&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver ya estamos conectados a la VPN SSL con el segundo factor de autenticación por mail:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_20.png?ssl=1" data-lbwps-width="878" data-lbwps-height="587" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12705" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_20.png?fit=878%2C587&amp;ssl=1" data-orig-size="878,587" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_20.png?fit=640%2C428&amp;ssl=1" class="aligncenter size-full wp-image-12705" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_20.png?resize=640%2C428&#038;ssl=1" alt="" width="640" height="428" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_20.png?w=878&amp;ssl=1 878w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_20.png?resize=595%2C398&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_20.png?resize=768%2C513&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?ssl=1" data-lbwps-width="1739" data-lbwps-height="697" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21-1536x616.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12706" data-permalink="https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/fsvcsfdaucde_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?fit=1739%2C697&amp;ssl=1" data-orig-size="1739,697" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="fsvcsfdaucde_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?fit=640%2C257&amp;ssl=1" class="aligncenter size-full wp-image-12706" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?resize=640%2C257&#038;ssl=1" alt="" width="640" height="257" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?w=1739&amp;ssl=1 1739w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?resize=595%2C238&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?resize=960%2C385&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?resize=768%2C308&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?resize=1536%2C616&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/12/fsvcsfdaucde_21.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/fortigate-ssl-vpn-con-segundo-factor-de-autenticacion-usando-cuenta-de-email/feed</wfw:commentRss>
			<slash:comments>11</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">12685</post-id>	</item>
		<item>
		<title>Forticlient EMS – Asignar perfiles de Endpoints a Grupos de equipos de Active Directory</title>
		<link>https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory</link>
					<comments>https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory#comments</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 28 Dec 2020 12:38:15 +0000</pubDate>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Forticlient]]></category>
		<category><![CDATA[Forticlient EMS]]></category>
		<category><![CDATA[Fortigate]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Suite de seguridad empresarial]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=12377</guid>

					<description><![CDATA[Hola a tod@s. En este post vamos a ver como asignar perfiles de Endpoints a Grupos de equipos de Active Directory. El primer perfil se lo vamos a asignar a los controladores de dominio, para ello, accedemos a Endpoints &#62;&#8230; <a href="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s.</p>
<p>En este post vamos a ver como asignar perfiles de Endpoints a Grupos de equipos de Active Directory.</p>
<ul>
<li>El primer perfil se lo vamos a asignar a los controladores de dominio, para ello, accedemos a <strong>Endpoints &gt; Domains &gt; Midominio &gt; Domain Controllers</strong> y le asignamos el perfil correspondiente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png?ssl=1" data-lbwps-width="1017" data-lbwps-height="700" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12378" data-permalink="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/femsapdeagdedad_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png?fit=1017%2C700&amp;ssl=1" data-orig-size="1017,700" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="femsapdeagdedad_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png?fit=640%2C441&amp;ssl=1" class="aligncenter size-full wp-image-12378" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png?resize=640%2C441&#038;ssl=1" alt="" width="640" height="441" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png?w=1017&amp;ssl=1 1017w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png?resize=595%2C410&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png?resize=960%2C661&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_1.png?resize=768%2C529&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Le indicamos que Si:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png?ssl=1" data-lbwps-width="1224" data-lbwps-height="264" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12379" data-permalink="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/femsapdeagdedad_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png?fit=1224%2C264&amp;ssl=1" data-orig-size="1224,264" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="femsapdeagdedad_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png?fit=640%2C138&amp;ssl=1" class="aligncenter size-full wp-image-12379" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png?resize=640%2C138&#038;ssl=1" alt="" width="640" height="138" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png?w=1224&amp;ssl=1 1224w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png?resize=595%2C128&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png?resize=960%2C207&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_2.png?resize=768%2C166&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Como podemos ver, el instalador de Forticlient, está pendiente de ser desplegado sobre uno de nuestros controladores de dominio:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?ssl=1" data-lbwps-width="1912" data-lbwps-height="669" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3-1536x537.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12380" data-permalink="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/femsapdeagdedad_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?fit=1912%2C669&amp;ssl=1" data-orig-size="1912,669" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="femsapdeagdedad_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?fit=640%2C224&amp;ssl=1" class="aligncenter size-full wp-image-12380" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?resize=640%2C224&#038;ssl=1" alt="" width="640" height="224" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?w=1912&amp;ssl=1 1912w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?resize=595%2C208&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?resize=960%2C336&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?resize=768%2C269&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?resize=1536%2C537&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_3.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos que Forticlient se ha desplegado correctamente sobre nuestro controlador de dominio:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?ssl=1" data-lbwps-width="1915" data-lbwps-height="700" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4-1536x561.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12381" data-permalink="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/femsapdeagdedad_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?fit=1915%2C700&amp;ssl=1" data-orig-size="1915,700" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="femsapdeagdedad_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?fit=640%2C234&amp;ssl=1" class="aligncenter size-full wp-image-12381" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?resize=640%2C234&#038;ssl=1" alt="" width="640" height="234" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?w=1915&amp;ssl=1 1915w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?resize=595%2C217&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?resize=960%2C351&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?resize=768%2C281&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?resize=1536%2C561&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_4.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>El segundo perfil se lo vamos a asignar a los servidores, para ello, accedemos a <strong>Endpoints &gt; Domains &gt; Midominio &gt; Servidores</strong> y le asignamos el perfil correspondiente:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_5.png?ssl=1" data-lbwps-width="821" data-lbwps-height="759" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12382" data-permalink="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/femsapdeagdedad_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_5.png?fit=821%2C759&amp;ssl=1" data-orig-size="821,759" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="femsapdeagdedad_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_5.png?fit=640%2C592&amp;ssl=1" class="aligncenter size-full wp-image-12382" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_5.png?resize=640%2C592&#038;ssl=1" alt="" width="640" height="592" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_5.png?w=821&amp;ssl=1 821w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_5.png?resize=595%2C550&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_5.png?resize=768%2C710&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Le indicamos que Si:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png?ssl=1" data-lbwps-width="1202" data-lbwps-height="263" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12383" data-permalink="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/femsapdeagdedad_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png?fit=1202%2C263&amp;ssl=1" data-orig-size="1202,263" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="femsapdeagdedad_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png?fit=640%2C140&amp;ssl=1" class="aligncenter size-full wp-image-12383" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png?resize=640%2C140&#038;ssl=1" alt="" width="640" height="140" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png?w=1202&amp;ssl=1 1202w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png?resize=595%2C130&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png?resize=960%2C210&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_6.png?resize=768%2C168&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Aquí vemos que Forticlient se ha desplegado correctamente sobre nuestros servidores:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="655" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7-1536x526.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12384" data-permalink="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/femsapdeagdedad_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?fit=1914%2C655&amp;ssl=1" data-orig-size="1914,655" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="femsapdeagdedad_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?fit=640%2C219&amp;ssl=1" class="aligncenter size-full wp-image-12384" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?resize=640%2C219&#038;ssl=1" alt="" width="640" height="219" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?resize=595%2C204&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?resize=960%2C329&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?resize=768%2C263&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?resize=1536%2C526&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_7.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Si accedemos al <strong>Dashboard &gt; Forticlient Status </strong>podemos ver que tenemos ocupadas 7 de las 10 licencias de las que disponemos:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?ssl=1" data-lbwps-width="1914" data-lbwps-height="887" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8-1536x712.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="12385" data-permalink="https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/femsapdeagdedad_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?fit=1914%2C887&amp;ssl=1" data-orig-size="1914,887" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="femsapdeagdedad_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?fit=640%2C297&amp;ssl=1" class="aligncenter size-full wp-image-12385" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?resize=640%2C297&#038;ssl=1" alt="" width="640" height="297" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?w=1914&amp;ssl=1 1914w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?resize=595%2C276&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?resize=960%2C445&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?resize=768%2C356&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?resize=1536%2C712&amp;ssl=1 1536w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/11/femsapdeagdedad_8.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/forticlient-ems-asignar-perfiles-de-endpoints-a-grupos-de-equipos-de-active-directory/feed</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">12377</post-id>	</item>
	</channel>
</rss>
