Skip to main content
Gypsy_Dave
New Member
February 17, 2020
Question

Is it possible to create site to site VPN where one connection has Dyndns.org IP?

  • February 17, 2020
  • 3 replies
  • 4790 views

Hi,

I have two sites I want to connect via a site to site VPN. Both sites have a FG and only site A has a fixed IP address from the ISP. Site B uses a dynamic IP address. Can I use something like Dyndns,org to get around this? 

 

The main problem is if the coax modem in site B get switched off it will loose its IP address. Then the Fortigate VPN configuration will be null. 

 

Thanks,

Rob

    3 replies

    LolleQ
    New Member
    February 17, 2020

    IPsec tunnel with Dynamic DNS as Remote Gateway + FortiGuard DDNS.

    sw2090
    SuperUser
    SuperUser
    February 18, 2020

    or if you want to do on cli:

     

    e.g. for an exsting ipsec tunnel:

     

    config vpn ipsec phase1-interface

      edit <phase1-name>

        set type ddns

        set remotegw-ddns = <ddns-fqdn>

      next

    end

     

    if you want to go back to static ip:

    edit phase1 again and do

     

    unset type

    unset remotegwe-ddns

    set remote-gw <ip>

     

    end

     

    BTW: in older FortiOSes the option was named "FQDN" or something like that.

    Gypsy_Dave
    New Member
    February 18, 2020

    ok thanks guys. I'll give it a go..

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!