Technical Tip: Importance of using Static IP, FQDN or DDNS in IPsec dial-up VPN configurations
| Description | This article describes why a static public IP, FQDN, or DDNS hostname should be used as the remote gateway reference when configuring IPsec dial-in VPN tunnels on FortiGate. A stable identifier improves peer matching, strengthens security, and prevents tunnel instability when the remote peer’s public IP changes. |
| Scope | FortiGate, FortiOS v7.2.x and later. |
| Solution | In IPsec dial-in deployments, FortiGate must reliably associate an incoming negotiation with the correct Phase 1 configuration. Using a predictable remote gateway reference (static IP / FQDN / DDNS) and an explicit peer identifier (when applicable) helps prevent negotiation failures, policy mismatches, and intermittent tunnel drops caused by changing ISP-assigned addresses. Why it matters:
Configuration best practices:
Example CLI configuration (dial-in / dynamic peer):
Additional recommendations:
Related documents |

