Skip to main content
douglas1942
New Member
November 27, 2021
Solved

IPSEC tunnel - does it need a dedicated IP address ?

  • November 27, 2021
  • 1 reply
  • 2961 views

Hello, I have a single public IP address on my Fortigate.

If I configured an IPSec tunnel using this address, will this interfere with my regular Internet bound traffic and incoming VIPs that also share this same public IP address ?

Or should I ask the ISP for an additional public IP address for my IPSEC tunnel ?

Thank you.

Best answer by kcheng

Hi,

 

You can use the same public IP for both IPSec tunnel and regular internet traffic as well as incoming VIPs for as long as the port is available for IPSec connection. It is not a requirement to have a dedicated public IP to run IPSec VPN:

Cookbook | FortiGate / FortiOS 6.0.0 | Fortinet Documentation Library

1 reply

kcheng
Staff & Editor
kchengAnswer
Staff & Editor
November 27, 2021

Hi,

 

You can use the same public IP for both IPSec tunnel and regular internet traffic as well as incoming VIPs for as long as the port is available for IPSec connection. It is not a requirement to have a dedicated public IP to run IPSec VPN:

Cookbook | FortiGate / FortiOS 6.0.0 | Fortinet Documentation Library