Projects
Banking and finance30 sitesFortiGate

India 30-Branch Rollout

A bank must connect 30 branch offices across India to its Mumbai data centre and the Chennai DR data centre over IPsec. You run it like a real change: design, pre-checks, a pilot branch, then waves, with faults hidden in the sites.

The network you will build

DC interconnectIPsec to-MUM (preferred)IPsec to-CHN (backup)PC-BR0110.20.1.10FGT-BR01Branch 01, PuneISP / InternetISP-AFGT-MUMMumbai DC 10.1.0.0/16FGT-CHNChennai DR 10.2.0.0/16SRV-MUM10.1.0.10SRV-CHN10.2.0.10

Branch 1 (Pune) has only an internet connection. The Mumbai and Chennai data centres are already live. Your job: connect the branch to both data centres with secure IPsec tunnels, so staff can reach the bank servers. Mumbai is the main path, Chennai is the backup.

Unlock to launch the lab5 tasks · about 45 minutes · FortiGate commands in a real console

What you will do in the lab

  1. 1Check before you start
    From the branch firewall, ping the ISP and both data centres. If any of them does not answer, you do not start the change.
  2. 2Build two tunnels
    Create the IPsec tunnels from the branch to Mumbai and to Chennai with the given security settings.
  3. 3Set the routes
    Send Mumbai traffic through the Mumbai tunnel and Chennai traffic through the Chennai tunnel. Add a backup route so Mumbai traffic can use Chennai if Mumbai fails.
  4. 4Allow the traffic
    Write the firewall policies that let the branch LAN talk to both data centres. This also brings the tunnels up.
  5. 5Prove it works
    Ping the Mumbai and Chennai servers from the branch PC and confirm both tunnels are up.

Every task is checked automatically from your real configuration. Stuck? Each task has a hint.

Keep this handy: addresses and settings

Branch 1 LAN10.20.1.0/25
Branch WAN (FGT-BR01)198.51.100.2
Mumbai DC network10.1.0.0/16
Mumbai WAN (FGT-MUM)203.0.113.2
Chennai DC network10.2.0.0/16
Chennai WAN (FGT-CHN)192.0.2.2
IKE version2
Encryption / hashaes256 / sha256
DH group14 (PFS on)
Pre-shared keyNK-Bank-Tunnel-Key-2026

After the pilot: the other 29 branches

Once branch 1 works, the same configuration is reused for every branch with only the numbers changed. Pick a branch to see its addresses.

VLAN 10 users10.20.7.0/25
VLAN 20 voice10.20.7.128/26
VLAN 99 management10.20.7.192/27
VLAN 30 guest10.20.7.224/27
Loopback10.255.7.1/32
Home data centreMumbai

Coming next in this project: pushing the template to waves of branches, and finding faults hidden in a few of them.

🎓 For educational purposes only — all devices are simulationsTerms of UsePrivacy PolicyVerify a certificate© 2026 Network Kings
CONFIG by Network Kings — an educational IT simulation platform for learning purposes only. It is not Cisco IOS, Junos, FortiOS or PAN-OS and contains no Cisco, Juniper, Fortinet or Palo Alto Networks software. Cisco, IOS, CCNA, CCNP, Juniper, JNCIA, JNCIS, JNCIP, Fortinet, FortiGate, FortiOS, NSE, Palo Alto Networks, PAN-OS and PCNSE are trademarks of their respective owners. Network Kings is not affiliated with or endorsed by Cisco Systems, Inc., Juniper Networks, Inc., Fortinet, Inc. or Palo Alto Networks, Inc.