In this example, you will allow transparent communication between two networks that are located behind different FortiGates at different offices using route-based IPsec VPN. The VPN will be created on both FortiGates by using the VPN Wizard's Site to Site - FortiGate template. In this example, one office will be referred to as HQ and the other will be referred to as Branch. 1. Configuring the HQ IPsec VPN On the HQ FortiGate, go to VPN > IPsec Wizard . Select the Site to Site template, and select FortiGate . In the Authentication step, set IP Address to the IP of the Branch FortiGate (in the example, 172.20.120.135 ). After you enter the gateway, an available interface will be assigned as the Outgoing Interface . If you wish to use a different interface, select it from the drop-down menu. Set a secure Pre-shared Key . In the Policy & Routing step, set the Local Interface . The Local Subnets will be added automatically. Set Remote