This website uses cookies essential to its operation, for analytics, and for personalized content. By continuing to browse this site, you acknowledge the use of cookies. For details on cookie usage on our site, read our Privacy Policy
Hello Kris,
You would want to remap these interfaces within the expedition tool to make this work. What fortinet considers a WAN interface is the interface facing the provider edge, which we could use as a zone interface but for IPSEC tunneling ideally you would use the tunnel interfaces provided within the PAN ( IPSEC set up is here https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGkCAK ) The pass through for these IPSEC VPN's would be your provider edge egress point and you could have multiple VPN's traversing this interface. So if you are going to just migrate over a single VPN from the interface WAN1 you would want remap it into a tunnel interface and the outgoing interface would be the publicly routable IP on an egress interface towards your provider but the tunnel interface will encapsulate the VPN packet across that interface.
... View more