Skip to main content
lrob
New Member
February 27, 2017
Question

DialupVPN with IPSEC Site-To-Site Tunnel

  • February 27, 2017
  • 3 replies
  • 5490 views

Hello All, 

 

I have a 2x FG100D running 5.4.3 and configured with a site-to-site IPSEC VPN tunnel via the wizard that works without issue.  My problem is I also want to add DialupVPN access for remote users. I understand I need to use PEER ID and have made several attempts using the wizard and custom tunnel setups to make this work.  Unfortunately I have not been successful. 

 

If I setup a dialupVPN using the wizard I have to go to the CLI to change the Peertype and peerid since changing the wizard-based tunnel to custom wont let me save because it is looking for a IPV6 DNS server.  However, I have no issues setting the peertype to one and ID to 1001 in the CLI. 

 

I then try to change the point-to-point tunnel via the CLI and the peertype is set to ANY - which I cannot change.  So, all of my VPN client attempts fail with a mismatched preshare key (to name a few). 

 

First question - can I even do this - have a point-to-point IPSEC full time tunnel with a handful of remote access users accessing the LAN? 

 

If so, is there some general guidance on how to do this? I would post configs but I have deleted them each time I fail hoping starting fresh will shed new light.  However, this is not working.

 

Thanks in advance for any input/assistance you can offer. 

 

Larry

    3 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    February 28, 2017

    Generally those are two different things and work independently if you're setting them up at a single FG. But if you're load-balancing between two 100Ds, dialup VPN would cause an issue due to randomness on the other ends when it comes in one FG and goes out another, which takes asymmetric routes. I don't know how to deal with this situation unless one of them is the primary and the other is the backup for a particular dialupVPN arrangement.    

    MikePruett
    New Member
    February 28, 2017

    Are the two Gates that are connected via IPSec using static IPs? Or is one of them configured as a dialup VPN as well?

    lrob
    lrobAuthor
    New Member
    February 28, 2017

    The two FG100Ds are at separate locations and have static IPs assigned.  

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!