Skip to main content
gatorHeel
New Member
June 19, 2013
Question

IPsec VPN (DynDNS to Static) + Dialup

  • June 19, 2013
  • 3 replies
  • 4580 views
We seem to have an issue when a point-2-point VPN is used in conjunction with a dial-up VPN (on the same IP). Only seems to happen when remote end has DynDNS. We get a pre-shared key mismatch error on the VPN dial interface, even though the request is actually coming from the DynDNS VPN interface. We have a FGT-60C (#1) with fixed public IP XXX.XXX.XXX.XXX. We have another FGT-60C (#2) with a dynamic IP and DynDNS hostname dyn.domain.com. These two devices have IPSec VPN configured, and the #1 unit also has a dial-up configuration enabled. Everything has worked fine in the past, however this seems to be triggered when a new IPsec tunnel is added or there is some type of configuration change. Currently when we have appropriate policies in place for the VPN-dial interface, the DynDNS VPN' s do not work. Take out the policies and now all of the DynDNS policies are functional. In our dialup configuration, we have peer options set to: Accept peer ID in dialup group (group name). FortiOS v4.0 MR2 P14 Any ideas?

    3 replies

    rwpatterson
    New Member
    June 20, 2013
    I have a couple of remote sites using dyndns addresses as well. Works all day long. I do not have any dialup policies though. What ' s the order of the policies? Are the destinations ' any' (sloppy), or just the devices the sources need to see (neat)?
    gatorHeel
    gatorHeelAuthor
    New Member
    June 20, 2013
    Had not thought to check the order of policies, one of the dial-up policies was not last, which I have changed so that it is. Also, I was using " any" as destination, not initially but I think in the process of troubleshooting and removing/recreating the configuration. Now using the subnet of the IPSec DHCP scope for the dial-up interface. Between the two, hopefully this will take care of it once and for all. Currently, the dial-up tunnel is functional and the DynDNS tunnels are up as well. Thank you for your help Bob!
    rwpatterson
    New Member
    June 20, 2013
    The old adage of not seeing the forest for the tress is coming to mind. I think we' ve all been there. Glad you' re functional once again.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.