Skip to main content
Contributor III
June 29, 2010
Question

ADSL with IPSec VPN

  • June 29, 2010
  • 6 replies
  • 8501 views
Hi All I have a ADSL line with one real IP. my fortigate firewall behind the ADSL. i create a port Forwarding on ADSL router. can we do the IPSec VPN in this situation.

    6 replies

    abelio
    SuperUser
    SuperUser
    June 29, 2010
    Hi, that´s the complicated approach to do the task and could limit further configs. Did you consider turn the adsl router into ´bridge mode´ and establish a clean pppoe connection from the Fortigate itself??
    Contributor III
    July 8, 2010
    Agree with Abelio, better configure the adsl router as bridge mode and configure the ppoe settings on the FG. in future if you consider abt ssl vpn, it would be more helpful to configure the dyndns and other things.
    Contributor III
    July 12, 2010
    Sorry I can' t do that becouse they are (ISP) given RJ11 Cable so i can' t connect that cable
    Contributor III
    July 12, 2010
    i think you are confused, ofcourse the RJ11 is connected to a modem(Router) and from the router you connected to the FG. So what we are saying that you can configure the bridge mode on the adsl modem router. if you go the connection settings you can find there is another option called bridge mode instead of the ppoe or whatever.. Bridge mode means that the device will not estalish the PPP link, it will only pass through the details to another device which is capable of handling the PPP - much like a modem. I didnt understand what you mean by you have a real IP, is that a public IP, if it is then what type of connection you using? is it ppoe or static?
    Jijoy
    New Member
    July 13, 2010
    Hello, I have been through the same situation and I found an easy solution. I had the ISP giving me an RJ11 output to the Modem and then RJ45 to the Fortinet. I tried in many modes on the Modem, but Fortinet did not pick up the Dynamic Public IP generated on the ADSL modem. I tried to directly connect the RJ11 on to FG but FG did not give me setting options which the ISP required for the ADSL to work. (FG might have this option now) This is what I did, I bought a D-Link DSL-322T (320 also works) modem. Connected ISP RJ11 to Modem and configured the Modem. This is only a modem (no router), so the RJ45 output from the Modem gives you the Public Dynamic IP. Connect this to Fortigate WAN1 or Wan2. Under Fortgate -> System -> Network -> Interface, Configure Wan1 or Wan2 -> Dynamic. This should Work J
    ede_pfau
    SuperUser
    SuperUser
    July 13, 2010
    @Jijoy: this was because the FG didn' t do the negotiations to connect to your ISP. As you described you put a DSL modem in front of the FG (connected to a WAN port), select System/Network/WAN1, and set the mode to " PPPoE" . Here you enter all the information needed to log in to your ISP. I do this for all FGs connected to ADSL/SDSL links routinely. There are so many different routers out there, all with different setups and quirks, that I don' t want to mess around with them. All routers can be configured to act just as a modem (" LLC bridge mode" , with D-Link " 1483 Bridged IP LLC" ). Then they will not negotiate with the ISP (and hence, never receive the public IP) but the Fortigate will. As an added benefit, configure the DynDNS notification on the FG.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.