Skip to main content
tahhan
New Member
February 23, 2025
Question

Configuring Site to Site VPN in FortiGate 300E

  • February 23, 2025
  • 3 replies
  • 1647 views

Hi,

 

Can I configure site to site vpn between 2 sites, one of them is dynamic IP address.

 

Thanks,

3 replies

AEK
SuperUser
SuperUser
February 23, 2025

Hi Tahhan

Sure you can. Your FortiGate with dynamic IP must be configured as dialup client.

https://docs.fortinet.com/document/fortigate/7.6.1/administration-guide/6896/fortigate-as-dialup-client

Hope it helps.

AEK
Toshi_Esumi
SuperUser
SuperUser
February 23, 2025

Or, just use DDNS that FTNT/FGT offers.

Toshi

AEK
SuperUser
SuperUser
February 23, 2025

Hi Toshi

You are right, DDNS is more adapted to s2s while dialup FGT client is adapted for multiple FGTs with dynamic IP connecting to a hub FGT, right?

Edit : I know I need to review my NSE4 lessons.

AEK
Dhruvin_patel
Staff
Staff
February 23, 2025

Hello T@tahhan

 

Yes, you can configure a site-to-site VPN between two sites using a FortiGate 300E, even if one of the sites has a dynamic IP address. Here are the general steps to achieve this:

 

1. Set up Dynamic DNS (DDNS) on the FortiGate with the dynamic IP address:
- Ensure the DDNS service is functioning correctly on the FortiGate.
- Configure the FortiGate to use FortiDDNS with a unique location name corresponding to the WAN interface.
- For detailed steps on configuring Dynamic DNS on FortiGate, you can refer to the link provided in the configuration guide.

 

2. Navigate to VPN -> IPSec tunnels on the FortiGate:
- Create a new tunnel.
- For the remote gateway, choose 'Dynamic DNS' and input the remote site's DDNS name.
- Select the external interface (WAN) that will be used to communicate with the remote site.

By following these steps, you can establish a site-to-site VPN between the FortiGate 300E and a remote site with a dynamic IP address.

 

ref:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-VPN-between-static-and-dynamic-IP-FQDN/ta-p/191815

 

Regards!