> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Transit Gateway to FortiGate Over the Internet Workflow

> This is not a common scenario. You would only set up this type of connection if you want to connect an Aviatrix Transit gateway to a firewall that is outside your Cloud service provider (for example, in a branch office or warehouse).

<Note>
  This is not a common scenario. You would only set up this type of connection
  if you want to connect an Aviatrix Transit gateway to a firewall that is
  outside your Cloud service provider (for example, in a branch office or
  warehouse).
</Note>

1. In CoPilot, navigate to Cloud Fabric > Gateways > Transit Gateways.
2. <a href={"/docs/enterprise/" + "10.1" + "/reference/ui/cloud-fabric/gateways#view-transit-gateways"}>Create a Transit gateway</a>
   that will connect to your FortiGate firewall.
3. To connect the transit VPC gateway to FortiGate, navigate to Networking >
   Connectivity > External Connections (S2C).
4. Click *+External Connection*.
5. In the Add External Connection dialog, configure the following:

| Field                   | Value                                                                                             |
| ----------------------- | ------------------------------------------------------------------------------------------------- |
| Connect Public Cloud to | External Device > BGP over IPsec                                                                  |
| Local Gateway           | Select the Transit gateway you created in step 2 above                                            |
| Local ASN               | The BGP AS number the Transit gateway will use to exchange routes with the external device.       |
| Remote ASN              | Enter the BGP AS number the external device will use to exchange routes with the Transit Gateway. |
| Remote Device IP        | This is the FortiGate WAN IP.                                                                     |

<Note>
  Ensure that the Local/Remote ASN and the Remote Device IP are correct before
  saving.
</Note>

6. Click *Save*.
7. [Download the configuration](https://legacy.docs.aviatrix.com/documentation/latest/network/external-connection-download-configuration.html).

   The following is a sample configuration based on the Site2Cloud configuration
   above.

   <img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate4.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=fbbd6390ee1f6e1e3e49ed156878538d" alt="Sample configuration based on Site2Cloud" width="1240" height="888" data-path="images/guides/connectivity/vpn/fortigate4.png" />

## Configuring the Fortinet FortiGate Firewall

1. Login into FortiGate and configure it as follows:
   1. Navigate to VPN > IPsec Tunnels.
   2. Click *+Create New*, and select *IPsec Tunnel*.
   3. In the VPN Creation Wizard, select the Custom template type.
   4. Populate the fields according to your preferences.
   5. Click *Next*.

### VPN Setup

| Field         | Expected Value |
| ------------- | -------------- |
| Name          | Any name       |
| Template Type | Custom         |

<img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate5.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=312ea4ebb33b9f492d25065d7e7d518a" alt="VPN Setup wizard" width="1243" height="309" data-path="images/guides/connectivity/vpn/fortigate5.png" />

### New VPN Tunnel Tab

2. Complete the Network fields on the New VPN Tunnel tab as follows:

**Network section of New VPN Tunnel tab**

| Field               | Expected Value                        |
| ------------------- | ------------------------------------- |
| IP Version          | IPv4                                  |
| Remote Gateway      | Static IP Address                     |
| IP Address          | Public IP address of Aviatrix Gateway |
| Interface           | Select the external port/interface    |
| Local Gateway       | Disabled                              |
| Mode Config         | Unchecked                             |
| NAT Traversal       | Recommended: Enable                   |
| Keepalive Frequency | Any value                             |
| Dead Peer Detection | On Demand                             |

<img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate6.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=dd2bbde1afe586bd54e2c9c1684f4816" alt="Network section of New VPN Tunnel tab" width="838" height="577" data-path="images/guides/connectivity/vpn/fortigate6.png" />

**Authentication section of New VPN Tunnel tab**

| Field          | Expected Value                                                                                                 |
| -------------- | -------------------------------------------------------------------------------------------------------------- |
| Method         | Pre-Shared Key                                                                                                 |
| Pre-shared Key | In the Pre-shared Key field, enter the value from the Pre-Shared Key row in the downloaded configuration file. |
| IKE Version    | 1                                                                                                              |
| IKE Mode       | Main (ID protection)                                                                                           |

<img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate7.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=9a1ce921566eb77838fae8b8145c840e" alt="Authentication section of New VPN Tunnel tab" width="861" height="258" data-path="images/guides/connectivity/vpn/fortigate7.png" />

**Phase 1 Proposal section of New VPN Tunnel tab**

| Field                  | Expected Value                                                                                                           |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| Encryption             | In the Encryption field, enter the value from the Encryption Algorithm row in the downloaded configuration file.         |
| Authentication         | In the Authentication field, enter the value from the Authentication Algorithm row in the downloaded configuration file. |
| Diffie-Hellman Group   | Select the appropriate value as per the Perfect Forward Secrecy row in the downloaded configuration file.                |
| Key Lifetime (seconds) | 28800                                                                                                                    |
| Local ID               |                                                                                                                          |

<img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate9.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=bad6289d94faf847c5c707cf75fb1edb" alt="Phase 1 Proposal section of New VPN Tunnel tab" width="803" height="278" data-path="images/guides/connectivity/vpn/fortigate9.png" />

**XAUTH section of New VPN Tunnel tab**

| Field | Expected Value |
| ----- | -------------- |
| Type  | Disabled       |

<img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate10.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=94c4bc87c423ab65dae0b706f55029ed" alt="XAUTH section of New VPN Tunnel tab" width="629" height="74" data-path="images/guides/connectivity/vpn/fortigate10.png" />

**Phase 2 Selectors > New Phase 2 section of New VPN Tunnel tab**

| Field          | Expected Value   |
| -------------- | ---------------- |
| Name           | Any string value |
| Comments       | Any string value |
| Local Address  | 0.0.0.0/0        |
| Remote Address | 0.0.0.0/0        |

<img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate11.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=4f395d42760311cfc0ddb19d6f103f02" alt="Phase 2 Selectors section of New VPN Tunnel tab" width="814" height="341" data-path="images/guides/connectivity/vpn/fortigate11.png" />

**Advanced section of New VPN Tunnel tab**

Click *+Advanced* to complete the fields listed below.

<Tip>Obtain the following values from the downloaded configuration file.</Tip>

| Field                  | Expected Value                                                                                                           |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| Encryption             | In the Encryption field, enter the value from the Encryption Algorithm row in the downloaded configuration file.         |
| Authentication         | In the Authentication field, enter the value from the Authentication Algorithm row in the downloaded configuration file. |
| Diffie-Hellman Group   | Select the appropriate value as per the Perfect Forward Secrecy row in the downloaded configuration file.                |
| Key Lifetime (seconds) | 28800                                                                                                                    |

<img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate13.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=b85f4abe06fd896650696f8a2d57b61d" alt="Advanced section of New VPN Tunnel tab" width="822" height="584" data-path="images/guides/connectivity/vpn/fortigate13.png" />

3. Click *OK*.

4. Navigate to Network > Interfaces.

5. Click on the Tunnel created above (e.g. aviatrix-gatew) and assign the IP
   address from the downloaded configuration file.

   <img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate14.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=0661ab1c8b47b2cc1a9ac6b19e18a609" alt="Tunnel interface IP assignment" width="1249" height="618" data-path="images/guides/connectivity/vpn/fortigate14.png" />

6. Click *OK*.

### Configure IPv4 Policy

1. Navigate to Policy & Objects > IPv4 DoS Policy.
2. Create two new IPv4 policies:
   1. Outbound traffic

      <img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate15.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=381c9892a8d1bf14862b7bd586325aa8" alt="Outbound traffic policy" width="544" height="226" data-path="images/guides/connectivity/vpn/fortigate15.png" />

   2. Inbound traffic

      <img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigate16.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=3c7ca959bc6aedb8e7c60fce424b3cc7" alt="Inbound traffic policy" width="539" height="223" data-path="images/guides/connectivity/vpn/fortigate16.png" />

<Note>
  The reference to *port2* in the screenshots should be replaced with your own
  interface name that represents the internal facing interface.
</Note>

<Note>Be sure to select *ACCEPT* for Action and select *ALL* for Service.</Note>

### IPSec Monitor

1. In the Fortigate UI, navigate to Dashboard > Network and click the IPsec
   widget.
2. Select the Aviatrix tunnel, and click *Bring Up*.
3. You can then check the tunnel status in CoPilot under Diagnostics > Cloud
   Routes.

### BGP

1. In the FortiGate UI, navigate to Network > BGP.

2. Configure the Local BGP Options as below:

   * RouterID: Tunnel IP address taken from the configuration file downloaded at
     step3
   * Neighbors: Remote tunnel IP address and ASN
   * Networks: All the networks needs to be advertised via BGP (here 10.0.3.0 is
     the local network of FortiGate)

   <img src="https://mintcdn.com/aviatrix-14b37c43/1zOMu4WXCFpEtXhJ/images/guides/connectivity/vpn/fortigatebgp.png?fit=max&auto=format&n=1zOMu4WXCFpEtXhJ&q=85&s=4a63ea45f252f806919235652c57b786" alt="BGP configuration" width="2112" height="864" data-path="images/guides/connectivity/vpn/fortigatebgp.png" />

3. In CoPilot, go to Diagnostics > Cloud Routes > BGP Info to verify the BGP
   Routes. The Status should be Established. If some external connections for
   the selected Transit Gateway are Not Established, the overall BGP Status for
   the Transit Gateway is Partially Established.
