Skip to main content

4 replies

AEK
SuperUser
SuperUser
December 20, 2024

Hi Andrea

These two articles should help.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-dial-up-full-tunnel-with-FortiClient/ta-p/189452

https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-configure-IPsec-VPN-Tunnel-using-IKE-v2/ta-p/196140

SD-WAN will not change anything to the IPsec configuration. In IPsec config you have to select the physical interface, not the SD-WAN interface. So if you need to use both WAN interfaces then you will have to create two IPsec tunnels on your FG (one on each interface).

AEK
it-andreagx
Explorer
December 23, 2024

Hello AEK, 

thank you for your reply, but really it doesn't seem that simple.
The classic configuration do not work with SDWAN.

Theo4
Explorer
December 22, 2024

Which article are you referring to? and what exactly do you mean by "connect SDWAN by FortiClient VPN"?

Dhruvin_patel
Staff
Staff
December 22, 2024

Greetings,

 

You can connect a FortiGate with FortiOS 7.4.6 using FortiClient VPN (IPsec) and integrate it with SD-WAN.

 

Create the dialup tunnel, then add the IPsec Interface to the SD-WAN.

 

Note: Please make sure that no policy with an IPsec tunnel is created; otherwise, adding an IPsec interface as a member in SD-WAN will not be allowed.

 

Regards!

If you have found a solution, please like and accept it to make it easily accessible for others.

it-andreagx
Explorer
December 23, 2024

Hello, 

the interface (WAN2) is part of SDWAN zone. 
So, we don't need any policies related to the tunnel associated with WAN2 and the SD-WAN zone?

Dhruvin_patel
Staff
Staff
December 24, 2024

I mean the policy associated with the IPsec tunnel's virtual interface.

There should not be any policy directly applied to the IPsec tunnel itself.

sw2090
SuperUser
SuperUser
December 23, 2024

At least in FOS 7.2. there is some bug with ipsec dial up and sdwan. Sdwan cannot correctly detect wether a dialup is up or not and in interface mode the interface itself is always up. This leads to sdwan not taking down unusable routes which causes routing trouble then.

I don't know if that has been fixed in 7.4.