{"id":928,"date":"2026-09-06T17:14:45","date_gmt":"2026-09-06T11:44:45","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/"},"modified":"2026-09-14T04:33:14","modified_gmt":"2026-09-13T23:03:14","slug":"fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/","title":{"rendered":"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example"},"content":{"rendered":"<div class=\"networkfix-source-box\"><strong>NetworkFix Technical Guide<\/strong><br \/>Configuration examples are designed for lab and reference use. Verify interface names, FortiOS version-specific options, cryptographic settings, and security policies against your production environment before deployment.<\/div>\n<p>Connecting geographically separated office networks securely is a core requirement for enterprise organizations. A <strong>FortiGate site to site IPsec VPN<\/strong> creates an encrypted route-based tunnel across untrusted public networks such as the internet. This setup allows private subnets at different locations to communicate as if they were on the same local network.<\/p>\n<p>This technical guide explains how to design, build, verify, and troubleshoot a route-based site-to-site IPsec VPN tunnel between two FortiGate firewalls using FortiOS. You will learn the mechanics of Phase 1 and Phase 2 negotiations, routing behavior, firewall policy enforcement, and practical CLI troubleshooting techniques.<\/p>\n<p><strong>Related NetworkFix resources:<\/strong> Explore the <a href=\"https:\/\/networkfix.in\/fortigate\/\">FortiGate security guides<\/a> for more FortiGate-focused content, or browse the <a href=\"https:\/\/networkfix.in\/tutorials\/\">Tutorials &amp; Guides<\/a> section for additional hands-on configuration walkthroughs.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>An enterprise organization operates a Head Office (HQ) in Chicago and a Branch Office in Austin. Both sites connect to local internet service providers (ISPs) using static public IP addresses.<\/p>\n<p>The organization requires seamless, secure communications between internal devices at both sites. Users in the Branch Office must access corporate database servers located at Head Office. HQ staff require direct management access to local branch servers. The traffic between both local area networks (LANs) must be encrypted without modifying internal host IP addressing.<\/p>\n<h2>Lab Topology<\/h2>\n<p>The following diagram illustrates the route-based VPN tunnel topology connecting the HQ FortiGate and the Branch FortiGate across the internet.<\/p>\n<pre>\n HQ Network                                 Internet                                Branch Network\n[10.10.10.0\/24]                                                                    [10.20.20.0\/24]\n       |                                                                                  |\n (port2: 10.10.10.1)                                                               (port2: 10.20.20.1)\n+--------------+                                                                  +--------------+\n| HQ-FortiGate |                                                                  | BR-FortiGate |\n+--------------+                                                                  +--------------+\n (port1: 198.51.100.2)                                                            (port1: 203.0.113.2)\n       |                                                                                  |\n       +--- [Gateway: 198.51.100.1] --- (IPsec VPN Tunnel) --- [Gateway: 203.0.113.1] ---+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The table below outlines the network subnets, interface assignments, public IPs, and object naming conventions used throughout this configuration guide. All values are labeled for lab\/example purposes.<\/p>\n<table>\n<thead>\n<tr>\n<th>Parameter \/ Object<\/th>\n<th>Head Office (HQ-FortiGate) [LAB]<\/th>\n<th>Branch Office (BR-FortiGate) [LAB]<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Public WAN Interface<\/strong><\/td>\n<td>port1 (198.51.100.2\/24)<\/td>\n<td>port1 (203.0.113.2\/24)<\/td>\n<\/tr>\n<tr>\n<td><strong>Default Gateway<\/strong><\/td>\n<td>198.51.100.1<\/td>\n<td>203.0.113.1<\/td>\n<\/tr>\n<tr>\n<td><strong>Internal LAN Interface<\/strong><\/td>\n<td>port2 (10.10.10.1\/24)<\/td>\n<td>port2 (10.20.20.1\/24)<\/td>\n<\/tr>\n<tr>\n<td><strong>Internal Subnet<\/strong><\/td>\n<td>10.10.10.0\/24<\/td>\n<td>10.20.20.0\/24<\/td>\n<\/tr>\n<tr>\n<td><strong>VPN Tunnel Name<\/strong><\/td>\n<td><code>HQ-to-Branch<\/code><\/td>\n<td><code>Branch-to-HQ<\/code><\/td>\n<\/tr>\n<tr>\n<td><strong>Local Address Object<\/strong><\/td>\n<td><code>ADDR_HQ_LAN<\/code> (10.10.10.0\/24)<\/td>\n<td><code>ADDR_BR_LAN<\/code> (10.20.20.0\/24)<\/td>\n<\/tr>\n<tr>\n<td><strong>Remote Address Object<\/strong><\/td>\n<td><code>ADDR_BR_LAN<\/code> (10.20.20.0\/24)<\/td>\n<td><code>ADDR_HQ_LAN<\/code> (10.10.10.0\/24)<\/td>\n<\/tr>\n<tr>\n<td><strong>Pre-Shared Key<\/strong><\/td>\n<td><code>EXAMPLE_SECRET_KEY_123<\/code><\/td>\n<td><code>EXAMPLE_SECRET_KEY_123<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before configuring a FortiGate site to site IPsec VPN, ensure the following prerequisites are met:<\/p>\n<ul>\n<li><strong>Static Public IP Addresses:<\/strong> Assign accessible static public IP addresses to both FortiGate WAN interfaces, or use dynamic DNS (DDNS) if dynamic WAN IPs are used.<\/li>\n<li><strong>Non-Overlapping Subnets:<\/strong> Verify that the local and remote internal network subnets do not overlap. If subnets overlap, destination NAT or virtual IP mapping is required.<\/li>\n<li><strong>Administrative Access:<\/strong> Ensure administrative access to both FortiGate devices via HTTPS or SSH.<\/li>\n<li><strong>Cryptographic Agreement:<\/strong> Align proposal settings prior to setup, including IKE version, encryption protocols, authentication algorithms, Diffie-Hellman (DH) groups, and Pre-Shared Keys (PSK).<\/li>\n<\/ul>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<p>This section walks through configuring the IPsec VPN tunnel using the FortiOS Graphical User Interface (GUI). Navigation paths may vary slightly depending on your FortiOS release and administrator profile settings.<\/p>\n<h3>Step 1: Configure Phase 1 and Phase 2 Tunnel Settings (HQ-FortiGate)<\/h3>\n<ol>\n<li>Log in to the HQ-FortiGate GUI.<\/li>\n<li>Navigate to <strong>VPN &gt; IPsec Tunnels<\/strong> and click <strong>Create New &gt; IPsec Tunnel<\/strong>.<\/li>\n<li>Enter a tunnel <strong>Name<\/strong> (for example, <code>HQ-to-Branch<\/code>). Select <strong>Custom<\/strong> build type and click <strong>Next<\/strong>.<\/li>\n<li>Under <strong>Network<\/strong> settings:\n<ul>\n<li>Set <strong>IP Version<\/strong> to <code>IPv4<\/code>.<\/li>\n<li>Set <strong>Remote Gateway<\/strong> to <code>Static IP Address<\/code>.<\/li>\n<li>Enter the remote public IP address in the <strong>Remote IP<\/strong> field: <code>203.0.113.2<\/code>.<\/li>\n<li>Set <strong>Interface<\/strong> to your internet-facing interface (for example, <code>port1<\/code>).<\/li>\n<\/ul>\n<\/li>\n<li>Under <strong>Authentication<\/strong>:\n<ul>\n<li>Set <strong>Method<\/strong> to <code>Pre-shared Key<\/code>.<\/li>\n<li>Enter the strong shared secret in the <strong>Pre-shared Key<\/strong> field.<\/li>\n<li>Set <strong>IKE Version<\/strong> to <code>2<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Under <strong>Phase 1 Proposal<\/strong>:\n<ul>\n<li>Set <strong>Encryption<\/strong> to <code>AES256<\/code> and <strong>Authentication<\/strong> to <code>SHA256<\/code>.<\/li>\n<li>Set <strong>DH Group<\/strong> to <code>14<\/code> (or higher, such as 19 or 20).<\/li>\n<li>Set <strong>Key Lifetime<\/strong> to <code>86400<\/code> seconds.<\/li>\n<\/ul>\n<\/li>\n<li>Expand <strong>Phase 2 Selectors<\/strong>:\n<ul>\n<li>Set <strong>Local Address<\/strong> to <code>Subnet<\/code> and enter <code>10.10.10.0\/255.255.255.0<\/code>.<\/li>\n<li>Set <strong>Remote Address<\/strong> to <code>Subnet<\/code> and enter <code>10.20.20.0\/255.255.255.0<\/code>.<\/li>\n<li>Under <strong>Advanced<\/strong>, set Encryption to <code>AES256<\/code> and Authentication to <code>SHA256<\/code>.<\/li>\n<li>Enable <strong>Auto-negotiate<\/strong> and <strong>Autokey Keep Alive<\/strong> if continuous tunnel initiation is required.<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong> to save the tunnel configuration.<\/li>\n<\/ol>\n<h3>Step 2: Create Address Objects and Static Routes (HQ-FortiGate)<\/h3>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Addresses<\/strong> and create address objects for <code>ADDR_HQ_LAN<\/code> (10.10.10.0\/24) and <code>ADDR_BR_LAN<\/code> (10.20.20.0\/24).<\/li>\n<li>Navigate to <strong>Network &gt; Static Routes<\/strong> and click <strong>Create New<\/strong>.<\/li>\n<li>Set <strong>Destination<\/strong> to <code>Subnet<\/code> and enter <code>10.20.20.0\/255.255.255.0<\/code>.<\/li>\n<li>Set <strong>Interface<\/strong> to the newly created VPN interface: <code>HQ-to-Branch<\/code>.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 3: Create Firewall Policies (HQ-FortiGate)<\/h3>\n<p>FortiOS requires active firewall policies to authorize traffic entering or exiting virtual IPsec interfaces.<\/p>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Firewall Policy<\/strong> and click <strong>Create New<\/strong>.<\/li>\n<li>Configure the Outbound Policy (LAN to VPN):\n<ul>\n<li><strong>Name:<\/strong> <code>HQ-to-Branch-Outbound<\/code><\/li>\n<li><strong>Incoming Interface:<\/strong> <code>port2<\/code> (LAN)<\/li>\n<li><strong>Outgoing Interface:<\/strong> <code>HQ-to-Branch<\/code> (VPN interface)<\/li>\n<li><strong>Source:<\/strong> <code>ADDR_HQ_LAN<\/code><\/li>\n<li><strong>Destination:<\/strong> <code>ADDR_BR_LAN<\/code><\/li>\n<li><strong>Service:<\/strong> <code>ALL<\/code><\/li>\n<li><strong>Action:<\/strong> <code>ACCEPT<\/code><\/li>\n<li><strong>NAT:<\/strong> Disabled (Ensure Source NAT is turned off).<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<li>Create the Inbound Policy (VPN to LAN):\n<ul>\n<li><strong>Name:<\/strong> <code>Branch-to-HQ-Inbound<\/code><\/li>\n<li><strong>Incoming Interface:<\/strong> <code>HQ-to-Branch<\/code> (VPN interface)<\/li>\n<li><strong>Outgoing Interface:<\/strong> <code>port2<\/code> (LAN)<\/li>\n<li><strong>Source:<\/strong> <code>ADDR_BR_LAN<\/code><\/li>\n<li><strong>Destination:<\/strong> <code>ADDR_HQ_LAN<\/code><\/li>\n<li><strong>Service:<\/strong> <code>ALL<\/code><\/li>\n<li><strong>Action:<\/strong> <code>ACCEPT<\/code><\/li>\n<li><strong>NAT:<\/strong> Disabled.<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<p>Repeat these step-by-step procedures on the Branch FortiGate, reversing local and remote subnet definitions, IP addresses, and policy directional flows.<\/p>\n<h2>CLI Configuration<\/h2>\n<p>Command Line Interface (CLI) configuration offers a fast, precise, and standardized implementation path. Below are the complete FortiOS CLI commands for both Head Office and Branch Office firewalls.<\/p>\n<h3>Head Office (HQ-FortiGate) CLI Configuration<\/h3>\n<pre>\n# Step 1: Create Firewall Address Objects\nconfig firewall address\n    edit \"ADDR_HQ_LAN\"\n        set subnet 10.10.10.0 255.255.255.0\n    next\n    edit \"ADDR_BR_LAN\"\n        set subnet 10.20.20.0 255.255.255.0\n    next\nend\n\n# Step 2: Configure Phase 1 Interface\nconfig vpn ipsec phase1-interface\n    edit \"HQ-to-Branch\"\n        set interface \"port1\"\n        set ike-version 2\n        set peertype any\n        set net-device disable\n        set proposal aes256-sha256\n        set dhgrp 14\n        set remote-gw 203.0.113.2\n        set psksecret EXAMPLE_SECRET_KEY_123\n        set dpd on-idle\n    next\nend\n\n# Step 3: Configure Phase 2 Interface\nconfig vpn ipsec phase2-interface\n    edit \"HQ-to-Branch-P2\"\n        set phase1name \"HQ-to-Branch\"\n        set proposal aes256-sha256\n        set dhgrp 14\n        set auto-negotiate enable\n        set src-subnet 10.10.10.0 255.255.255.0\n        set dst-subnet 10.20.20.0 255.255.255.0\n    next\nend\n\n# Step 4: Configure Static Route\nconfig router static\n    edit 0\n        set dst 10.20.20.0 255.255.255.0\n        set device \"HQ-to-Branch\"\n    next\nend\n\n# Step 5: Configure Firewall Policies\nconfig firewall policy\n    edit 0\n        set name \"HQ-Outbound-To-Branch\"\n        set srcintf \"port2\"\n        set dstintf \"HQ-to-Branch\"\n        set srcaddr \"ADDR_HQ_LAN\"\n        set dstaddr \"ADDR_BR_LAN\"\n        set action accept\n        set schedule \"always\"\n        set service \"ALL\"\n    next\n    edit 0\n        set name \"HQ-Inbound-From-Branch\"\n        set srcintf \"HQ-to-Branch\"\n        set dstintf \"port2\"\n        set srcaddr \"ADDR_BR_LAN\"\n        set dstaddr \"ADDR_HQ_LAN\"\n        set action accept\n        set schedule \"always\"\n        set service \"ALL\"\n    next\nend\n<\/pre>\n<h3>Branch Office (BR-FortiGate) CLI Configuration<\/h3>\n<pre>\n# Step 1: Create Firewall Address Objects\nconfig firewall address\n    edit \"ADDR_BR_LAN\"\n        set subnet 10.20.20.0 255.255.255.0\n    next\n    edit \"ADDR_HQ_LAN\"\n        set subnet 10.10.10.0 255.255.255.0\n    next\nend\n\n# Step 2: Configure Phase 1 Interface\nconfig vpn ipsec phase1-interface\n    edit \"Branch-to-HQ\"\n        set interface \"port1\"\n        set ike-version 2\n        set peertype any\n        set net-device disable\n        set proposal aes256-sha256\n        set dhgrp 14\n        set remote-gw 198.51.100.2\n        set psksecret EXAMPLE_SECRET_KEY_123\n        set dpd on-idle\n    next\nend\n\n# Step 3: Configure Phase 2 Interface\nconfig vpn ipsec phase2-interface\n    edit \"Branch-to-HQ-P2\"\n        set phase1name \"Branch-to-HQ\"\n        set proposal aes256-sha256\n        set dhgrp 14\n        set auto-negotiate enable\n        set src-subnet 10.20.20.0 255.255.255.0\n        set dst-subnet 10.10.10.0 255.255.255.0\n    next\nend\n\n# Step 4: Configure Static Route\nconfig router static\n    edit 0\n        set dst 10.10.10.0 255.255.255.0\n        set device \"Branch-to-HQ\"\n    next\nend\n\n# Step 5: Configure Firewall Policies\nconfig firewall policy\n    edit 0\n        set name \"BR-Outbound-To-HQ\"\n        set srcintf \"port2\"\n        set dstintf \"Branch-to-HQ\"\n        set srcaddr \"ADDR_BR_LAN\"\n        set dstaddr \"ADDR_HQ_LAN\"\n        set action accept\n        set schedule \"always\"\n        set service \"ALL\"\n    next\n    edit 0\n        set name \"BR-Inbound-From-HQ\"\n        set srcintf \"Branch-to-HQ\"\n        set dstintf \"port2\"\n        set srcaddr \"ADDR_HQ_LAN\"\n        set dstaddr \"ADDR_BR_LAN\"\n        set action accept\n        set schedule \"always\"\n        set service \"ALL\"\n    next\nend\n<\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding internal packet processing inside FortiOS helps engineers design robust networks and isolate issues quickly. The following sequence details how an unencrypted IP packet travels from a source host at Head Office to a server at Branch Office.<\/p>\n<ol>\n<li><strong>Ingress &amp; Routing Lookup:<\/strong> A computer on HQ LAN (<code>10.10.10.50<\/code>) sends an IP packet to a branch server (<code>10.20.20.100<\/code>). The packet arrives at HQ FortiGate interface <code>port2<\/code>. The FortiGate inspects its routing table. It finds a static route for <code>10.20.20.0\/24<\/code> pointing out virtual interface <code>HQ-to-Branch<\/code>.<\/li>\n<li><strong>Firewall Policy Matching:<\/strong> FortiOS evaluates active firewall policies. It checks for a match with incoming interface <code>port2<\/code>, egress interface <code>HQ-to-Branch<\/code>, source address <code>10.10.10.50<\/code>, and destination address <code>10.20.20.100<\/code>. The firewall permits the traffic because it matches policy ID 1 (outbound policy).<\/li>\n<li><strong>IPsec SA Match &amp; Encapsulation:<\/strong> The packet enters the virtual tunnel interface. FortiOS matches the destination subnet against Phase 2 Security Association (SA) traffic selectors. The engine encapsulates the original IP packet inside an Encapsulating Security Payload (ESP) header (IP protocol 50) and encrypts the payload using AES-256.<\/li>\n<li><strong>Egress Delivery:<\/strong> The original packet payload is encrypted. FortiOS prefixes a new outer IP header with source <code>198.51.100.2<\/code> and destination <code>203.0.113.2<\/code>. The packet leaves the physical <code>port1<\/code> interface towards the public gateway.<\/li>\n<li><strong>Remote Decapsulation &amp; Policy Evaluation:<\/strong> The Branch FortiGate receives the ESP packet on <code>port1<\/code>. It looks up the SPI (Security Parameter Index), decrypts the outer payload using the agreed SA keys, and extracts the inner packet (<code>10.10.10.50<\/code> -&gt; <code>10.20.20.100<\/code>).<\/li>\n<li><strong>Egress to Destination:<\/strong> The Branch FortiGate evaluates its inbound firewall policy from ingress interface <code>Branch-to-HQ<\/code> to egress interface <code>port2<\/code>. Upon matching the permit policy, the packet exits interface <code>port2<\/code> and reaches host <code>10.20.20.100<\/code>.<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>Confirm IPsec tunnel operation, state negotiation, routing table integration, and end-to-end dataplane connectivity using the following verification steps.<\/p>\n<h3>1. Check Phase 1 Status<\/h3>\n<p>Execute the following command to verify whether Phase 1 IKE negotiation is established:<\/p>\n<pre>diagnose vpn ike gateway list name HQ-to-Branch<\/pre>\n<p>Look for status output showing <code>established<\/code>, along with valid local\/remote network addresses and assigned SPI entries.<\/p>\n<h3>2. Check Phase 2 Status<\/h3>\n<p>Verify active Security Associations and packet byte counts using:<\/p>\n<pre>diagnose vpn tunnel list name HQ-to-Branch-P2<\/pre>\n<p>The output must display established SAs with incrementing packet counters for both outbound (<code>sa_out<\/code>) and inbound (<code>sa_in<\/code>) security associations.<\/p>\n<h3>3. Verify Active Route Table<\/h3>\n<p>Confirm the static route targeting the remote subnet is active in the routing table:<\/p>\n<pre>get router info routing-table all<\/pre>\n<p>Ensure an entry exists for <code>10.20.20.0\/24<\/code> pointing directly to interface <code>HQ-to-Branch<\/code>.<\/p>\n<h3>4. Dataplane Connectivity Test<\/h3>\n<p>Initiate a source-based ICMP echo request from the FortiGate CLI using the internal interface IP address as the source:<\/p>\n<pre>execute ping-options source 10.10.10.1\nexecute ping 10.20.20.1<\/pre>\n<p>A successful ping response proves routing, tunnel encapsulation, decryption, and firewall policies are operating correctly end-to-end.<\/p>\n<h2>Troubleshooting<\/h2>\n<p>When an IPsec tunnel fails to connect or pass traffic, follow a structured workflow to isolate the root cause.<\/p>\n<h3>Troubleshooting Workflow<\/h3>\n<ol>\n<li><strong>Physical\/Link Layer:<\/strong> Verify WAN interfaces have valid IP addresses and reachability to the remote public gateway.<\/li>\n<li><strong>Phase 1 IKE Diagnostics:<\/strong> Validate credentials, cryptographic proposals, and port 500\/4500 reachability.<\/li>\n<li><strong>Phase 2 SA Diagnostics:<\/strong> Check traffic selector consistency (subnets) and perfect forward secrecy (PFS) settings.<\/li>\n<li><strong>Routing &amp; Policy Checks:<\/strong> Verify return routes exist on both ends and firewall policies match traffic flows.<\/li>\n<li><strong>Dataplane Verification:<\/strong> Run debug flow engine traces to inspect packet handling steps.<\/li>\n<\/ol>\n<h3>Troubleshooting Matrix<\/h3>\n<table>\n<thead>\n<tr>\n<th>Symptom<\/th>\n<th>Probable Root Cause<\/th>\n<th>Resolution \/ Verification Check<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Phase 1 Status down (No response)<\/td>\n<td>Incorrect Remote IP, blocked UDP 500\/4500, or network unreachable.<\/td>\n<td>Verify remote public IP. Ping remote IP from physical interface. Check upstream router ACLs.<\/td>\n<\/tr>\n<tr>\n<td>Phase 1 fails with <code>negotiation failure<\/code><\/td>\n<td>Mismatch in Pre-Shared Key (PSK), IKE Version, or Phase 1 Proposals.<\/td>\n<td>Run IKE application debugs to confirm phase 1 parameter mismatches.<\/td>\n<\/tr>\n<tr>\n<td>Phase 1 up, Phase 2 down<\/td>\n<td>Mismatched Phase 2 encryption algorithms, PFS group, or traffic selectors.<\/td>\n<td>Align phase 2 proposals and confirm subnet masks match on both firewalls.<\/td>\n<\/tr>\n<tr>\n<td>Tunnel fully up, but traffic fails<\/td>\n<td>Missing static route, missing firewall policy, or active Source NAT.<\/td>\n<td>Check routing table (`get router info routing-table all`). Ensure NAT is disabled on policy.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Real-Time Debug Commands<\/h3>\n<p>Execute real-time IKE tracing to diagnose negotiation failures:<\/p>\n<pre>\ndiagnose debug reset\ndiagnose debug application ike -1\ndiagnose debug enable\n<\/pre>\n<p>Observe the live terminal output to identify mismatch errors (such as <code>PSK mismatch<\/code> or <code>no proposal chosen<\/code>).<\/p>\n<p>Execute packet tracing with the FortiGate packet diagnostic engine to observe routing and policy evaluation for specific traffic:<\/p>\n<pre>\ndiagnose debug reset\ndiagnose debug flow filter saddr 10.10.10.50\ndiagnose debug flow filter daddr 10.20.20.100\ndiagnose debug flow show console enable\ndiagnose debug flow trace start 10\ndiagnose debug enable\n<\/pre>\n<p><em>Caution: Real-time debug commands consume CPU and memory resources. Always disable debugging routines immediately after collecting diagnostic data.<\/em><\/p>\n<p>To safely clean up debug traces, run:<\/p>\n<pre>\ndiagnose debug flow trace stop\ndiagnose debug disable\ndiagnose debug reset\n<\/pre>\n<h2>Common Mistakes<\/h2>\n<ul>\n<li><strong>Enabling NAT on Firewall Policies:<\/strong> Enabling Source NAT on IPsec policies changes host source IPs into WAN or interface IPs, preventing proper Phase 2 selector matching or causing asymmetric reply paths. Keep NAT disabled for normal site-to-site policy rules.<\/li>\n<li><strong>Mismatched Phase 2 Selectors:<\/strong> Defining <code>10.10.10.0\/24<\/code> local and <code>10.20.20.0\/24<\/code> remote on HQ, but incorrectly entering <code>10.10.0.0\/16<\/code> on the Branch side will cause Phase 2 negotiation to fail immediately. Ensure exact mirror configurations.<\/li>\n<li><strong>Missing Return Routes:<\/strong> Setting up outgoing routes on HQ while forgetting to set up return routes on the Branch firewall leads to unidirectionally encrypted traffic that drops at the remote endpoint.<\/li>\n<li><strong>Forgetting Dynamic Policy Definitions:<\/strong> FortiOS requires policies for incoming traffic from the tunnel interface to local LAN interfaces. Outbound-only policy configurations block return traffic packets.<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>To ensure high availability, optimal performance, and security for enterprise deployments, apply the following production practices:<\/p>\n<ul>\n<li><strong>Prefer IKEv2 over IKEv1:<\/strong> IKEv2 provides faster connection re-establishment, lower bandwidth overhead, native NAT traversal support, and superior error handling compared to IKEv1.<\/li>\n<li><strong>Enable Dead Peer Detection (DPD):<\/strong> Configure DPD on both endpoints (e.g., <code>set dpd on-idle<\/code>) so FortiGate quickly detects dead peers and cleans up stale SAs.<\/li>\n<li><strong>TCP MSS Clamping:<\/strong> Encapsulation overhead reduces the effective MTU available for transit packets. Adjust TCP MSS options on the IPsec phase1 interface to prevent fragmentation drops:\n<pre>\nconfig vpn ipsec phase1-interface\n    edit \"HQ-to-Branch\"\n        set tcp-mss-sender 1380\n        set tcp-mss-receiver 1380\n    next\nend\n<\/pre>\n<\/li>\n<li><strong>SD-WAN Integration:<\/strong> In dual-ISP environments, terminate separate IPsec tunnels over each ISP circuit and group them into an SD-WAN zone. This allows automated performance-based failover and load balancing across redundant site-to-site tunnels.<\/li>\n<\/ul>\n<h2>Related FortiGate Guides<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/troubleshoot-fortigate-ipsec-vpn-phase-1-and-phase-2-problems\/\">FortiGate IPsec VPN troubleshooting<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-remote-access-ipsec-vpn-configuration-and-verification\/\">FortiGate remote-access IPsec VPN<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-session-troubleshooting-with-flow-debug-sessions-and-logs\/\">FortiGate session troubleshooting<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/\">FortiGate HA and failover<\/a><\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Building a <strong>FortiGate site to site IPsec VPN<\/strong> requires clear alignment of Phase 1 connection settings, Phase 2 network selectors, route tables, and firewall access policies. A route-based design provides flexible network control by decoupling encapsulation logic from policy filtering, allowing seamless scalability across complex enterprise topologies.<\/p>\n<div class=\"networkfix-takeaway\"><strong>NetworkFix Takeaway<\/strong><br \/>For a reliable site-to-site VPN, validate the complete path\u2014not just tunnel status: Phase 1, Phase 2 selectors, routing, firewall policies, NAT behavior, and bidirectional traffic counters all need to align.<\/div>\n<div class=\"networkfix-related\">\n<h2>Related FortiGate Resources<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/fortigate\/\">Browse all FortiGate security guides<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/tutorials\/\">Explore NetworkFix Tutorials &amp; Guides<\/a><\/li>\n<\/ul>\n<\/div>\n<p>For the next step, see the <a href=\"https:\/\/networkfix.in\/fortigate\/\">NetworkFix FortiGate section<\/a> for related firewall configuration guides and troubleshooting content.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A practical FortiGate site-to-site IPsec VPN guide with a branch-office topology, GUI and CLI configuration, verification steps, troubleshooting, and production considerations.<\/p>","protected":false},"author":2,"featured_media":927,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[4],"tags":[29,41,135,44,43,73,116],"class_list":["post-928","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fortinet","tag-firewall-tutorial","tag-fortigate","tag-fortigate-site-to-site-ipsec-vpn","tag-fortinet","tag-fortios","tag-intermediate","tag-vpn"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>FortiGate Site-to-Site IPsec VPN: Branch Office Guide<\/title>\n<meta name=\"description\" content=\"Configure a FortiGate site-to-site IPsec VPN between HQ and branch offices with GUI, CLI, routing, firewall policies, verification, and troubleshooting.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example\" \/>\n<meta property=\"og:description\" content=\"Configure a FortiGate site-to-site IPsec VPN between HQ and branch offices with GUI, CLI, routing, firewall policies, verification, and troubleshooting.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-06T11:44:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T23:03:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example\",\"datePublished\":\"2026-09-06T11:44:45+00:00\",\"dateModified\":\"2026-09-13T23:03:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/\"},\"wordCount\":1852,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg\",\"keywords\":[\"Firewall Tutorial\",\"FortiGate\",\"FortiGate site to site IPsec VPN\",\"Fortinet\",\"FortiOS\",\"Intermediate\",\"VPN\"],\"articleSection\":[\"FortiGate\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/\",\"name\":\"FortiGate Site-to-Site IPsec VPN: Branch Office Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg\",\"datePublished\":\"2026-09-06T11:44:45+00:00\",\"dateModified\":\"2026-09-13T23:03:14+00:00\",\"description\":\"Configure a FortiGate site-to-site IPsec VPN between HQ and branch offices with GUI, CLI, routing, firewall policies, verification, and troubleshooting.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg\",\"width\":1200,\"height\":630,\"caption\":\"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"FortiGate Site-to-Site IPsec VPN: Branch Office Guide","description":"Configure a FortiGate site-to-site IPsec VPN between HQ and branch offices with GUI, CLI, routing, firewall policies, verification, and troubleshooting.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/","og_locale":"en_US","og_type":"article","og_title":"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example","og_description":"Configure a FortiGate site-to-site IPsec VPN between HQ and branch offices with GUI, CLI, routing, firewall policies, verification, and troubleshooting.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/","og_site_name":"NetworkFix","article_published_time":"2026-09-06T11:44:45+00:00","article_modified_time":"2026-09-13T23:03:14+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg","type":"image\/jpeg"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example","datePublished":"2026-09-06T11:44:45+00:00","dateModified":"2026-09-13T23:03:14+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/"},"wordCount":1852,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg","keywords":["Firewall Tutorial","FortiGate","FortiGate site to site IPsec VPN","Fortinet","FortiOS","Intermediate","VPN"],"articleSection":["FortiGate"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/","url":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/","name":"FortiGate Site-to-Site IPsec VPN: Branch Office Guide","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg","datePublished":"2026-09-06T11:44:45+00:00","dateModified":"2026-09-13T23:03:14+00:00","description":"Configure a FortiGate site-to-site IPsec VPN between HQ and branch offices with GUI, CLI, routing, firewall policies, verification, and troubleshooting.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-example-featured.jpg","width":1200,"height":630,"caption":"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-site-to-site-ipsec-vpn-configuration-with-a-branch-office-ex\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"FortiGate Site-to-Site IPsec VPN Configuration with a Branch Office Example"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/928","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=928"}],"version-history":[{"count":6,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/928\/revisions"}],"predecessor-version":[{"id":1565,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/928\/revisions\/1565"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/927"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}