Skip to main content
jpapic
Explorer
April 1, 2026
Question

FexExternder IPsec VPN

  • April 1, 2026
  • 1 reply
  • 111 views

Te lo dejo mejorado para foro (más claro, técnico y natural :backhand_index_pointing_down::(


Hi all,

I’m working on a Hub-and-Spoke IPsec VPN setup where the Spoke site is using a FortiExtender (LTE) as the WAN interface.

I would like to know if there are any special considerations or required configurations when using a FortiExtender on the Spoke side.

Currently, I’m facing the following error:

"fext_wan IP is 0"

It seems related to the LTE interface, which is expected to obtain its IP dynamically.

 

Thanks in advance.

1 reply

SkylarDe
New Member
April 5, 2026

Setting this up usually depends on how your FortiExtender is connected. If you have it in 'Bridge mode,' the FortiGate should treat the LTE interface just like a regular WAN, making the IPsec setup much smoother. If it’s in 'NAT mode,' you’ll likely need to account for the double NAT by using a DDNS address or setting up the VPN to 'Aggressive Mode' so the FortiGate can identify the peer correctly.