Skip to main content
Alex2000
New Member
May 4, 2024
Solved

Ensuring VPN redundancy

  • May 4, 2024
  • 17 replies
  • 4453 views

I have 2 VPN servers. I configure them in the list when setting up the VPN client. If the first server is unavailable, the client does not connect to the second server. Am I doing something wrong?

image.png

Best answer by Alex2000

7.0.7 it is work !!!!!

 

new version bug !

17 replies

funkylicious
SuperUser
SuperUser
May 4, 2024

Hi,

I assume that each DNS entry resolves in a different IP ?

If so, on the FGT itself do you have two static routes for 0.0.0.0/0 or a sdwan config ?

 

L.E. under ssl vpn settings, you have both IPs listed under listening on interface ?

"jack of all trades, master of none"
Alex2000
Alex2000Author
New Member
May 4, 2024

made up addresses, for example. But in my case, yes - these are 2 different fortigates. They both work if you use them by swapping them in the list. But if I turn off the first one in the list, the client does not try to connect to the second one in the same list

funkylicious
SuperUser
SuperUser
May 4, 2024

hmm, not sure about multiple remote gateways from different devices how and if it would/should work, only multiple links on the same device.

"jack of all trades, master of none"
Alex2000
Alex2000Author
New Member
May 4, 2024

After all, the manufacturer has made it possible to add multiple VPN connections. Why are they needed then?

funkylicious
SuperUser
SuperUser
May 4, 2024

for this scenario i guess

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-SSL-VPN-Access-for-two-different/ta-p/192904

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-Redundancy/ta-p/189668?externalID=FD46628


what you are trying to do in your case might work and maybe something else is not working/configured as it should on both devices

"jack of all trades, master of none"
Alex2000
Alex2000Author
New Member
May 5, 2024

Apparently you do not understand the essence of the question. Everything is fine between the two fortigates. The client does not attempt to connect to the second one if there is no connection with the first Fortigate. I have 2 different Fortigates in different country data centers

funkylicious
SuperUser
SuperUser
May 6, 2024

Most likely I've misunderstood your issue since you mentioned 2 FGTs.

So, if I understand correctly both DNS entries are different links on the same device and you have 2 such devices with similar issues and when the first configured remote gw configured in FCT is shutdown or disabled, the 2nd remote gw is not being selected/used, is that correct ?

If so, is the sslvpn portal available, can it be reached/accessed for the 2nd one when the first is unavalable ?

You can also have a look at this, if its not already enabled https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enabling-the-preserve-session-route/ta-p/197976

"jack of all trades, master of none"
hbac
Staff
Staff
May 6, 2024

Hi @Alex2000,

 

I tested in my lab and it worked. Are you able to resolve the second FQDN from the client? Can you run packet sniffer on the second FortiGate to see if it receives the traffic or not. 

 

di sniffer packet any 'port 10443' 4 0 l

 

Regards, 

Alex2000
Alex2000Author
New Member
May 6, 2024


I can use IP addresses instead of DNS, this is not a problem.

 

Untitled.jpg

 

Alex2000
Alex2000Author
New Member
May 6, 2024

You got it wrong again. These are completely different devices. They are located in different countries. But both of them perform the same function - access to the company’s corporate resources. You can connect to any of them and get a home connection to the company’s intranet. I want to indicate them in a list, so that if one device does not respond (broken), the second one responds and gives a connection. But the Forty client does not attempt to connect to the second server in the list.

Alex2000
Alex2000Author
New Member
May 6, 2024

bad.jpggood.jpg

 


in one case there is only one server in the list that responds well. In another case, I move the same server second in the list. And the first one I register is a obviously non-existent IP. The connection will go on forever to the first one in the list, and there will be no attempt on the second one

 

Alex2000
Alex2000Author
New Member
May 6, 2024

he pictures are mixed up but I think you understand

funkylicious
SuperUser
SuperUser
May 6, 2024

I tried myself this setup, using a fake IP address as first Remote Gateway and the 2nd the real IP+port and worked as intended.

When I entered the user/password combo, it went to status Connecting then to about 30%, then it returned by itself to the user/password screen were it was asking me to input them again, then after 2s it connected to the 2nd remote gw because I saw the Connecting status again and went to MFA input.

Maybe it has something to do with the fact that you are using a FortiClient ZTNA edition, try downloading the VPN only version.

"jack of all trades, master of none"
Alex2000
Alex2000AuthorAnswer
New Member
May 7, 2024

7.0.7 it is work !!!!!

 

new version bug !

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!