Skip to main content
Contributor III
June 21, 2011
Question

Multiple ip address in vpn

  • June 21, 2011
  • 4 replies
  • 3780 views
Hi , In fortigate 3000 Is their an option in vpn site to site at phase 1 to enter more than one ip range as the remote gateway ? thanks

    4 replies

    Matthijs
    New Member
    June 21, 2011
    Why do you need this? You cannot add it over there, but vpn is site-to-site so from 1 site to another. If you have 2 lines between the sites you should create 2 vpn' s and user 2 static routes with equal distance to load balance...
    Contributor III
    June 21, 2011
    the remote gateway has two external interfaces (for load balance) with two different ip address. some times the traffic comes from one ip and some times from the other and i need the same vpn tunnel for these address.
    ede_pfau
    SuperUser
    SuperUser
    June 21, 2011
    Hi, no you can' t do that. Create 2 VPN tunnels and load balance them on your side. The gateway IP address is part of the tunnel negotiations/SPI and cannot be IP1 now and IP2 later. If the remote side uses 2 gateways there is still no need to tackle this. Assuming the remote side opens the tunnel, to your ONE gateway address. All is fine as the remote side will not use it' s other interface in between to send data over the tunnel. If your side opens the tunnel you just decide to use one of the remote gateway' s IP addresses. Only if you want to have load balanced VPN tunnels you will have to follow the advice from the previous post. It involves some work and knowledge in setting up and trouble shooting so I would consider the pros and cons.
    Contributor III
    June 22, 2011
    thanks .
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!