Skip to main content
yeowkm99
New Member
November 25, 2024
Question

IP address for ipsec tunnel

  • November 25, 2024
  • 4 replies
  • 1425 views

is there any limit on the IP address that I can used for ipsec site-to-site tunnels from fortinet firewall to 3rd party firewall like in AWS cloud.

currently we have site-to-site ipsec using 172.xx.xx.xx/16 as our MPLS network are all in the range 172.16.0.0 to 172.32.0.0/16.

Can we do IP subnet out of this range?

4 replies

DPadula
Staff & Editor
Staff & Editor
November 25, 2024

Hi yeowkm99,

 

I don't see any reason why you couldn't not subnet the range 172.x.x.x/16 for the IPSec tunnel. 

sjoshi
Staff
Staff
November 27, 2024

Hi there is no limit on the IP subnet range.

Make sure the quick mode selectors on both ends are same

Thanks, Salon
yeowkm99
yeowkm99Author
New Member
November 28, 2024

any issues if i create ipsec tunnels to 2 difference 3rd party using the same subnets?

eg 172.25.0.0/16 souce, 172.30.0.0/16 destination and 172.25.0.0/16 source, 172.28.0.0/16 destination both with difference WAN IP address. 

sjoshi
Staff
Staff
November 28, 2024

Hi,

 

there will be no issue.

else you can also use VIP, IP pool concept.

refer:-

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/426761/site-to-site-vpn-with-overlapping-subnets

Thanks, Salon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!