# MPLS + Internet IPSEC SDWAN 設定

### **<span style="color: rgb(22, 145, 121);">設計概念 ：</span>**

 HQ透過MPLS連線到各分點，同時針對某些較重要的分點透過MPLS+Internet 建立雙線備援，以防網路連線中斷。

#### <span style="color: rgb(35, 111, 161);">**一、<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">概念架構圖。</span>**</span>

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/image.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/image.png)

#### <span style="color: rgb(35, 111, 161);">**<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">二、先設定好</span> <span lang="EN-US">MPLS</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">、</span><span lang="EN-US">Internet Interface</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">與路由。</span>**</span>

HQ Interface設定:

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/eXximage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/eXximage.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/m2Zimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/m2Zimage.png)

HQ 路由:

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/Oj8image.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/Oj8image.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/BTlimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/BTlimage.png)

Internet Interface與路由請比照MPLS設定，DR端亦然

至於到其他分點的路由就照常設定MPLS的Static Route即可

#### <span style="color: rgb(35, 111, 161);">**<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">三、設定<span lang="EN-US">MPLS</span>、<span lang="EN-US">Internet</span>到<span lang="EN-US">DR</span>的<span lang="EN-US">IPSEC VPN</span>，使用自定義模式。</span>**</span>

 以下僅用MPLS IPSEC示範，Internet IPSEC請自行比照設定

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/mpfimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/mpfimage.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/d5jimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/d5jimage.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/BgEimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/BgEimage.png)

兩條IPSEC建立好之後如下圖

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/8OUimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/8OUimage.png)

#### **<span style="color: rgb(35, 111, 161);"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">五、至</span><span lang="EN-US">Interface</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">將</span><span lang="EN-US">VPN</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">介面設定</span><span lang="EN-US">IP</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">，兩邊的設備互相設</span></span><span style="color: rgb(35, 111, 161);"><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">定</span></span>**

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/GKyimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/GKyimage.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/0Puimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/0Puimage.png)

<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;"><span lang="EN-US">FortiOS 7.0</span>版會出現錯誤，使用<span lang="EN-US">CLI</span>設定</span>

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/bJqimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/bJqimage.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/6HJimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/6HJimage.png)

**<span style="color: rgb(224, 62, 45);">注意 !! </span>**此處設定IPSEC VPN Interface的 IP是用來作路由使用，上圖為HQ端設定，DR端請自行比照設定

以此範例為例

HQ Internet IPSEC VPN Interface 為 10.1.1.14、DR Internet IPSEC VPN Interface 為 10.1.1.13

HQ MPLS IPSEC VPN Interface 為 10.1.1.10、DR MPLS IPSEC VPN Interface 為 10.1.1.9

#### <span style="color: rgb(35, 111, 161);">**<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">六、建立</span><span lang="EN-US">SDWAN Zone</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">，將兩個</span><span lang="EN-US">IPSEC VPN Interface</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">加進去</span><span lang="EN-US">Member</span>**</span>

<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;"> 完成HQ與DR的上述設定後並加完之後應該就可以正常將IPSEC</span><span lang="EN-US">VPN Turnnel</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">帶起來，此時互</span><span lang="EN-US">Ping</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">對方的</span><span lang="EN-US">IPSEC VPN Interface IP</span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">應該就要會通了。</span>

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/EvUimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/EvUimage.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/xIdimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/xIdimage.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/SN5image.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/SN5image.png)

#### <span style="color: rgb(35, 111, 161);">**<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">七、設定<span lang="EN-US">SDWAN Rule</span></span>**</span>

<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;"> </span><span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">下圖為HQ端SDWAN Rule，DR端請自行比照設定</span>

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/3CRimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/3CRimage.png)

#### <span style="color: rgb(35, 111, 161);">**<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">八、設定<span lang="EN-US">Firewall Policy</span>、<span lang="EN-US">Static Route</span></span>**</span>

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/W7mimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/W7mimage.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/OL9image.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/OL9image.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/oE1image.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/oE1image.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/fv0image.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/fv0image.png)

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/07qimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/07qimage.png)

<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;"><span lang="EN-US"> 設定完成後Ping DR LAN Interface</span>應該就要會通了。</span>

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/I8Limage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/I8Limage.png)

**<span style="color: rgb(224, 62, 45);">注意 !! </span>**一樣HQ、DR都要設定，否則也不會通

#### <span style="color: rgb(35, 111, 161);">**<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;">九、設定<span lang="EN-US">SDWAN</span>線路偵測機制，互相指對方的<span lang="EN-US">LAN Interface</span>即可。</span>**</span>

<span style="font-family: '新細明體',serif; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: minor-fareast; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;"> 透過兩條線路去跟對方的LAN Interface作Health Check，如果Check異常則將線路直接下線，用以確保資料傳輸的正確性。</span>

[![image.png](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/scaled-1680-/vfIimage.png)](https://mdfk.goddamn.idv.tw/uploads/images/gallery/2024-06/vfIimage.png)