FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
vkulik
Staff
Staff
Article Id 192244
Description

IPSec VPN maybe implemented in tunnel mode (default mode on the FortiGate), or now also in transport mode since FortiOS 4.0MR2.

Tunnel mode is mostly used for Gateway-to-Gateway connections, as well as to connect proprietary VPN clients to VPN gateway (like FortiClient, Cisco VPN Client, CheckPoint SecureClient, etc...).

Transport mode may be used between end-stations supporting IPSec, or between an end-station and a gateway.


Scope
FortiOS 4.0MR2 and above

Solution
The configuration is available only from CLI :

config vpn ipsec phase2
     edit <PHASE2_NAME_HERE>
     set encapsulation transport-mode
end


The other settings are similar to regular tunnel mode configuration

Contributors