Skip to main content
ejellis
Visitor III
April 29, 2025
Question

How to create dial-in IPSEC VPN with 2 wans for failover redundancy

  • April 29, 2025
  • 11 replies
  • 4792 views

I've been searching and searching on the best way to do this.  I need to configure redundant dial in IPSEC VPN for FortiClient users.  Meaning If WAN1's internet is down WAN2 will kick in and work Just like in an SD-WAN failover situation.  I have not been able to find a clear answer on a config to do this.  I know how to implement SD-WAN over IPSEC in a site to site config but there doesn't seem to be a clear config for dial in users using Forti Client.  Any help is appreciated.

 

 

11 replies

funkylicious
SuperUser
SuperUser
April 29, 2025

i think that a failover/backup ipsec dialup configuration would be kinda hard to achieve, unless the same public subnet would be available through both WANs/ISPs.

 

if so, i think that you could create a loopback interface used in IPsec config and create VIP for UDP/500 and UDP/4500 towards it using a public IP that could be reached from both connections.

"jack of all trades, master of none"
ejellis
ejellisAuthor
Visitor III
April 29, 2025

I've looked into that as well and the only downside to it is you lose hardware acceleration using a loopback interface.    I wish it was  as easy as it is with SSL VPN where you set it to listen to both WANs in the setup.   Since SSL VPN is going extinct I've got to find a better solution

funkylicious
SuperUser
SuperUser
April 29, 2025

maybe try using a fqdn as remote gateway having a dns entry for both wans / having 2 ipsec tunnels configured, one for each interface

 

L.E. something like described here, https://docs.fortinet.com/document/forticlient/7.4.3/ems-administration-guide/622574/load-balancing-ipsec-vpn-gateways-with-a-single-fqdn 

"jack of all trades, master of none"
ejellis
ejellisAuthor
Visitor III
April 29, 2025

Thanks for the great input everyone.  I will give this a try in my lab.  I think I was over thinking this a bit.  I will give an update once I've completed testing

ejellis
ejellisAuthor
Visitor III
April 29, 2025

Not having any luck with both gateways in the forti-client.  I have configured VPN's for both WAN's  and can connect to both individually.  Simulating one going down it never attempts to connect to the second gateway. Times out and does not connect .

mattxp
New Member
October 16, 2025

Hey did you ever get this figured out?

jwildner
New Member
December 5, 2025

I passtrought the same demand here, maybe the best options is count with the free DDNS service from fortinet, created a DNS alias with booth WAN interface, of course this is free service and have some inconsistence, best shoot should be have a GSLB or any other Loadbalance capable to test if the circurt is UP and update the DNS automatically in case a wan failure

I'm about to test with free DDNS service from fortigate

Abdullah_Siddiqui25
New Member
December 8, 2025

Hi @jwildner 

 

Were you able to achieve this with Fortigate DDNS service?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!