This article demonstrates how to establish an IPsec VPN tunnel between a FortiGate firewall and a DrayTek Vigor Router. The example below is based on FortiOS 7.0.
1. Create an IPsec VPN Tunnel
Go to VPN >> IPsec Tunnels, then click + Create New to create a new VPN profile. Enter a name for the tunnel, select Custom as the Template Type, and click Next.
2. Configure the Network Settings
Under Network Settings:
3. Configure Phase 1 (IKE) Settings
Under Authentication Settings:
4. Configure Phase 2 Settings
Under Phase 2 Settings:
Click Advanced to configure the Phase 2 proposal and set the Key Lifetime. The default Phase 2 lifetime on the Vigor Router is 3600 seconds.
5. Create an Address Object
Go to Policy & Objects >> Addresses, then click Create New >> Address.
Configure the following:
Click OK to save the configuration.
6. Create Firewall Policies
Go to Policy & Objects >> IPv4 Policy, then click Create New.
Create two firewall policies:
Note: Ensure the IPsec policies have a higher priority than general firewall rules. If necessary, manually adjust the policy order so that VPN traffic is matched before other policies (except management-related rules).
7. Create a Static Route
Go to Network >> Static Routes, then click Create New.
Click OK to apply the configuration.
1. Enable the IPsec Service
Go to VPN and Remote Access >> General Setup >> IPsec.
2. Create an IPsec VPN Profile
Go to VPN / Site-to-Site VPN.
Click +Add to create a new VPN profile. Enter a Profile Name and enable the profile.
General
IKE Authentication
TCP/IP Network Settings
Click Apply to save the profile.
3. Verify the VPN Connection
After the configuration is complete, the Vigor Router will automatically establish the IPsec tunnel if Always On is selected.
You can verify the VPN status by going to VPN / VPN Connection Status.
The tunnel status should be displayed as Connected once the VPN is successfully established.

Published On:2026-06-23
ShareWas this helpful?