Question
IPsec VPN (DynDNS to Static) + Dialup
We seem to have an issue when a point-2-point VPN is used in conjunction with a dial-up VPN (on the same IP). Only seems to happen when remote end has DynDNS. We get a pre-shared key mismatch error on the VPN dial interface, even though the request is actually coming from the DynDNS VPN interface. We have a FGT-60C (#1) with fixed public IP XXX.XXX.XXX.XXX. We have another FGT-60C (#2) with a dynamic IP and DynDNS hostname dyn.domain.com. These two devices have IPSec VPN configured, and the #1 unit also has a dial-up configuration enabled. Everything has worked fine in the past, however this seems to be triggered when a new IPsec tunnel is added or there is some type of configuration change. Currently when we have appropriate policies in place for the VPN-dial interface, the DynDNS VPN' s do not work. Take out the policies and now all of the DynDNS policies are functional. In our dialup configuration, we have peer options set to: Accept peer ID in dialup group (group name). FortiOS v4.0 MR2 P14 Any ideas?
