IPSec VPN maybe implemented in tunnel mode (default mode on the FortiGate), or now also in transport mode since FortiOS 4.0MR2.
Tunnel mode is mostly used for Gateway-to-Gateway connections, as well as to connect proprietary VPN clients to VPN gateway (like FortiClient, Cisco VPN Client, CheckPoint SecureClient, etc...).
Transport mode may be used between end-stations supporting IPSec, or between an end-station and a gateway.
config vpn ipsec phase2 edit <PHASE2_NAME_HERE> set encapsulation transport-mode end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.