> For the complete documentation index, see [llms.txt](https://docs.monogoto.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.monogoto.io/advanced-console/platform/vpn-setup-examples/vpn-setup-with-fortinet.md).

# VPN Setup with Fortinet

1\. Log in to the Monogoto portal and go to *Network.*

2\. Edit your **“vpneu.mono”** network (EU zone) or **"vpnus.mono"** network (US zone).

<figure><img src="/files/fB3J3TXink81m5wvf6TA" alt=""><figcaption></figcaption></figure>

3\. Go to Address Pools and copy IP Address/Mask.

<figure><img src="/files/d53a4J5cPXjDWWcyGJqQ" alt=""><figcaption></figcaption></figure>

4\. Go to Routes and copy Gateway IP.

<figure><img src="/files/0FLr0lmbo9aZWn0YC29q" alt=""><figcaption></figcaption></figure>

5\. Now we need to add a Route to the VPN in Monogoto portal -> Network -> Routes section and Add new

Destination = VPN IP address and mask\
Gateway = select Monogoto gateway\
Save and Close -> Apply Settings

6\. Lets add a VPN on the Monogoto portal. Please go to Network -> VPN section and Add a new VPN.

Destination IP Address = Fortinet Networks Tunnel Outside IP Address\
Destination Network = Fortinet Networks VPC IPv4 CIDR\
Pool Name = Select your pool\
Save and Close -> Apply Settings

<figure><img src="/files/Lfbxd2UCli9KLeoxGe2f" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/8UlNlwTpq66ufY1cHOUw" alt=""><figcaption></figcaption></figure>

7\. Now that we have created the VPN on the Monogoto end, download a VPN config file that will have all of the needed information for VPN configuration on the Fortinet Networks end.

<figure><img src="/files/BSJbRtjLvzMD5QNRslDp" alt=""><figcaption></figcaption></figure>

&#x20;To set up the VPN on the Fortinet, First we will set up a VPN using the wizard, and then we will customize it

&#x20;8\. Go to the Fortinet user interface.

9. Got to:\
   9.1 VPN->IPsec Wizard and:\
   9.2  Give the VPN name,\
   9.3  Chose Site-to-Site,\
   9.4  This site is behind NAT,\
   9.5  Remote device Cisco,\
   9.6 Press “Next”

<figure><img src="/files/5NxASvsKK44AtAEFGeBY" alt=""><figcaption></figcaption></figure>

10. On this page:\
    10.1 Set the Remote IP address of Monogoto GateWay,\
    10.2 Chose the outgoing interface of your Fortinet WAN,\
    10.3 Copy the Pre-Shared Key\
    10.4 Press “Next”

<figure><img src="/files/P8SSv4e8CaXUNXMgO4Aw" alt=""><figcaption></figcaption></figure>

&#x20;11\. On this page:

&#x20;       11.1 Set the Local interface\
&#x20;       11.2 Set the Local Subnet\
&#x20;       11.3 Set the remote Subnet (the subnet of the SIM cards)\
&#x20;       11.4 Press "Create"

<figure><img src="/files/n9F5wD934aZ0AKqLOtlU" alt=""><figcaption></figcaption></figure>

12\. On the main menu go to VPN -> IPsec Tunnels, find the new IPsec tunnel we created, and double-click it

<figure><img src="/files/kBHWKrywtCJ5Qa3lI3Wf" alt=""><figcaption></figcaption></figure>

&#x20;13\. In order to change the default values press the "Convert To Custom Tunnel" button

<figure><img src="/files/3OEbNSazyYwKK2TyqLcq" alt=""><figcaption></figcaption></figure>

&#x20;14\. Press edit on the Phase 1 Proposal

<figure><img src="/files/Dga7MrFaxOfaUIZ38XFZ" alt=""><figcaption></figcaption></figure>

&#x20;15\. Set:

&#x20;      15.1 Encryption to AES128\
&#x20;       15.2 Authentication to SHA1\
&#x20;       15.3 Diffie-Helman Group to “2”\
&#x20;       15.4 Key Lifetime 28800 sec

<figure><img src="/files/vZpBH6w8EG6NkjRR8mnd" alt=""><figcaption></figcaption></figure>

&#x20;16 Press “edit” of Phase 2 Selecter:

<figure><img src="/files/kW9n6uNstELNe54aARSH" alt=""><figcaption></figcaption></figure>

&#x20;17\. Set:

&#x20;     17.1 Encryption to AES128\
&#x20;      17.2 Authentication to SHA1\
&#x20;      17.3 Diffie-Helman Group to “2”\
&#x20;      17.4 Key Lifetime to 3600 sec

<figure><img src="/files/SlZXoI0LqTzq51hwa2Rm" alt=""><figcaption></figcaption></figure>

18\. Press OK at the bottom to save all changes. The IPsec Tunnel should be UP in a few seconds

<figure><img src="/files/525nCxzLlqzXcmrDIL2s" alt=""><figcaption></figcaption></figure>

&#x20;19\. Go back to Monogoto portal Network -> VPN. Check if our created VPN status is shown as Connected, if it is not, please press on Refresh button.

<figure><img src="/files/NPwcDifaFnEBCZse6lYL" alt=""><figcaption></figcaption></figure>

20\. When the status of the VPN is Connected, you may check the connection by doing a ping. You can do this by pressing on Ping button.

<figure><img src="/files/4gdLYfQLD1VIxi0QOjc7" alt=""><figcaption></figcaption></figure>

That's all, now the VPN tunnel is connected.

&#x20;
