Skip to main content
0skarprez
New Member
July 10, 2020
Question

2 IPsec connections over one interface

  • July 10, 2020
  • 2 replies
  • 9197 views

Hello, 

 

I hope you can help me, recently I was asked to configure another IPsec connection for remote users, with different policies. so I did it and everything worked properly, but I had not notice that, when I created the second IPsec connection, the fisrt one stop working, users cannot connect to that vpn connection, but the sencond works perfect. Once I deleted this second VPN connection, the first wan works again. Is this even possible, to have 2 differen IPsec connection through the same internet interface an IP address?, Did I miss something in the configuration?

 

We have a Fortigate 60D with v5.2.7,build718 (GA) SO. I know is an old one.

 

thank you for your comments.

regards

    2 replies

    rwpatterson
    New Member
    July 10, 2020

    This should work as long as you tighten up the phase 2 selectors. If you have them open to 0.0.0.0, the firewall may have a hard time discerning which one to drive traffic through. I do this all day as do most folks here so I know it works.

    0skarprez
    0skarprezAuthor
    New Member
    July 10, 2020

    Thank you for you comment, I am not sure how to configure that, this is what I have since I used the VPN wizard, and I think is exactly what you mentioned, 

     

    0skarprez
    0skarprezAuthor
    New Member
    July 10, 2020

    sorry, here is the image..

    Toshi_Esumi
    SuperUser
    SuperUser
    July 10, 2020

    If you're trying to set up two dialup/remote access VPNs for two different group, you need to user "Peer ID/Local ID" discussed in below:

    https://forum.fortinet.com/tm.aspx?tree=true&m=184280&mpage=1

    In the discussion, ShawnZA is referring to below KB:

    https://kb.fortinet.com/kb/documentLink.do?externalID=10114