Back to Learning
Fortinet · NSE 4

FortiGate Policy & IPsec VPN

Standing up two FortiGate appliances just to practice a site-to-site VPN is out of reach for most home labs. This lab gives you two live FortiOS gateways already networked, so you go straight to policy and tunnel configuration.

The problem

A site-to-site IPsec tunnel between two FortiGates refuses to come up. Both sides show the tunnel as configured, but Phase 1 never seems to finish.

What you'll practice

  • Configure firewall policies on FortiOS
  • Set up SD-WAN rules across multiple links
  • Build a site-to-site IPsec VPN between two FortiGate gateways
  • Verify phase 1 / phase 2 IPsec negotiation
  • Troubleshoot a tunnel that won't come up

The topology

Two FortiGate gateways, each fronting a small local network, connected over a simulated WAN link, the standard site-to-site topology used to practice IPsec VPN and SD-WAN policy.

Topology diagram

Locked

Enter your email to see the root cause behind FortiGate Policy & IPsec VPN, free.

No spam. The root cause lands in your inbox too. The full fix is part of the Learning Pass.

Frequently asked

Do I need two physical FortiGate appliances?

No. Both FortiOS gateways are already provisioned and networked. You configure policy and the VPN tunnel, nothing to rack.

Is this relevant to NSE 4?

Firewall policy, SD-WAN and IPsec VPN are core NSE 4 topics. This lab is scoped directly to that exam.

Ready to run this lab yourself?

No setup, no image sourcing. Book a session or ask for a live demo.