/tool fetch url="https://downloads.nordcdn.com/certificates/root.der"
/certificate import file-name=root.der
/ip ipsec profile
add name=NordVPN
/ip ipsec proposal
add name=NordVPN pfs-group=none
/ip ipsec policy group
add name=NordVPN
/ip ipsec policy add dst-address=0.0.0.0/0 group=NordVPN proposal=NordVPN src-address=0.0.0.0/0 template=yes
/ip ipsec mode-config
add name=NordVPN responder=no
/ip ipsec peer
add address=nl125.nordvpn.com exchange-mode=ike2 name=NordVPN profile=NordVPN
/ip ipsec identity
add auth-method=eap certificate="" eap-methods=eap-mschapv2 generate-policy=port-strict mode-config=NordVPN peer=NordVPN policy-template-group=NordVPN username=NordVPN-Username password=NordVPN-Password
/ip firewall address-list
add address=192.168.88.0/24 list=local
/ip ipsec mode-config
set [ find name=NordVPN ] src-address-list=local
/ip firewall nat print
/ip ipsec mode-config
add name=Fortigate-GW responder=no src-address-list=Fortigate-VPN-Access
/ip ipsec policy group
add name=Fortigate-GW
/ip ipsec profile
add dh-group=modp2048 enc-algorithm=aes-256 hash-algorithm=sha256 name=\
Fortigate-GW-Phase-1
/ip ipsec peer
add address=8.8.8.8/32 comment=Fortigate-GW disabled=yes exchange-mode=\
aggressive name=Fortigate-GW profile=Fortigate-GW-Phase-1
/ip ipsec proposal
add enc-algorithms=aes-256-gcm lifetime=12h name=Fortigate-GW-Phase-2 pfs-group=\
modp2048
/ip ipsec identity
add auth-method=pre-shared-key-xauth generate-policy=port-strict mode-config=\
Fortigate-GW password=xMG3Anf52eH9 peer=Fortigate-GW policy-template-group=Fortigate-GW \
secret=43e2LT2vsSRb username=vpn-user
/ip ipsec policy
add comment=Fortigate-GW disabled=yes dst-address=0.0.0.0/0 group=Fortigate-GW \
proposal=Fortigate-GW-Phase-2 src-address=0.0.0.0/0 template=yes
/ip firewall address-list
add address=192.168.133.0/24 list=Fortigate-VPN-Access
/ip ipsec mode-config
add address=192.168.40.99 name=Shrew-Mode-Config
/ip ipsec policy group
add name=Shrew-Group
/ip ipsec profile
add dh-group=modp1024 name=Shrew-Profile
/ip ipsec peer
add comment=Shrew-Peer exchange-mode=aggressive name=Shrew-Peer passive=yes \
profile=Shrew-Profile
/ip ipsec proposal
add lifetime=12h name=Shrew-Proposal
/ip ipsec identity
add auth-method=pre-shared-key-xauth comment=Shrew-Identities \
generate-policy=port-strict mode-config=Shrew-Mode-Config password=xMG3Anf52eH9 \
peer=Shrew-Peer policy-template-group=Shrew-Group secret=43e2LT2vsSRb username=\
vpn-user
/ip ipsec policy
add comment=Shrew-Policies dst-address=0.0.0.0/0 group=Shrew-Group proposal=\
Shrew-Proposal src-address=0.0.0.0/0 template=yes