Skip to main content
TryNewThings
Visitor III
February 17, 2022
Question

Layer 2 Device Hosting a VPN to provide Remote Fortigate

  • February 17, 2022
  • 1 reply
  • 1417 views

Hello There,

 

I have a use case whereby we dont have access to the layer 3 device to provision an IPSec connection. Furthermore, the network is managed by a third party, so we cant migrate the LAN to a new Router/Firewall.

 

This means our only option to gain access to the client devices on the network is via VPN software/hardware tool which is installed as a layer 2 device. This could be Rasberry Pi, Windows Server, Windows 10, Linux etc.

 

TryNewThings_0-1645091721858.png

 

The only Layer 2 Device solution im aware of is the Windows Routing and Remote Access (RRAS)

 

However, I dont beleive the FortiGate can connect to a SSTP VPN?

 

Any clever solutions welcome :)

 

Thank you in advance.

 

1 reply

Markus_M
Staff & Editor
Staff & Editor
February 17, 2022

Hey,

 

you will likely need to know first how either of the two endpoints can contact each other.

Otherwise accessing a stranger network would be rather inseucre.

 

If you cannot manage the firewall in between you likely cannot do a port forward to the raspi.

You could however use strongswan/libreswan for example to connect to the known IP address of the FGT with a dialup VPN. So connect from inside the network to the firewall.

 

Example:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-LibreSwan-for-a-site-to-site-IPSec-tunnel/ta-p/197548

 

Best regards,

 

Markus

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!