OSPF over IPsec configuration
There are several steps to the OSPF-over-IPsec configuration:
• Configure a route-based IPsec VPN on an external interface. It will connect to a corresponding interface on the other FortiGate unit. Define the two tunnel-end addresses.
• Configure a static route to the other FortiGate unit.
• Configure the tunnel network as part of the OSPF network and define the virtual IPsec interface as an OSPF interface.
This section describes the configuration with only one VPN, tunnel_wan1. The other VPN is added in the section
“Creating a redundant configuration”.