Skip to main content
needhelp22
New Member
February 4, 2025
Question

Establish multiple IPsec VPN via single WAN on FG

  • February 4, 2025
  • 2 replies
  • 1636 views

Hi all, I'm planning to do SDWAN with my current setup, but I've to admit that my setup might not be optimal. Currently the setup is, LAN --- HQ FG --(Single WAN)-- LB (3 WANs) -- Internet -- (Single WAN) -- Branch FG.

My plan, was to build 3 IPsec VPN tunnels, and implement SDWAN over it. So the best performance tunnel will be selected automatically. I tried a few methods but I failed,

1. Secondary IP with different segment on HQ FG, configure Port Forward (or VIP) on LB, each WAN maps to one specific IP.

2. Loopback interface with different segment on HQ FG, configure Port Forward (or VIP) on LB, each WAN maps to one specific IP.

3. Peer ID, Local ID.

4. Network-overlag, network-id.

 

I'd like to seek for help on how can I achieve my plan with SDWAN. Appreciate any help, and thanks in advance!

2 replies

Stephen_G
Staff & Editor
Staff & Editor
February 6, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen_G - Fortinet Community Team
Anthony_E
Staff
Staff
February 10, 2025

Hello,

 

I will answer to the question: how to establish multiple IPsec VPN tunnels via a single WAN interface on FortiGate, you can follow these steps:

  1. Configure the Phase 1 settings for each VPN tunnel:  Navigate to VPN -> IPsec -> Phase1 Interfaces. - Create a new Phase 1 configuration for each VPN tunnel. - Specify the necessary parameters such as interface, encryption algorithms, DH group, key lifetime, peer type, remote gateway, and pre-shared key.
  2. Configure the Phase 2 settings for each VPN tunnel:  Navigate to VPN -> IPsec -> Phase2 Interfaces. - Create a new Phase 2 configuration for each VPN tunnel. - Set the appropriate parameters like the Phase 1 name, encryption algorithms, DH group, and key lifetime.
  3. Configure the WAN interface settings:  Go to Network -> Interfaces. - Edit the WAN interface that will be used for the VPN tunnels. - Set the IP address and other necessary configurations for the WAN interface.
  4. Ensure proper routing:  Configure routing to direct traffic for each VPN tunnel through the WAN interface.
Best Regards
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!