Skip to main content
AMINET
New Member
March 13, 2023
Solved

Purpose of tunnel interface ip when use sd wan

  • March 13, 2023
  • 1 reply
  • 2791 views

Hi

In many tutorials when configuring ipsec vpn via sd wan that the tunnel interface must have an IP address, so my question is what is the purpose of this IP address and if the sd wan can work without ?

 

 

THANKS

Best answer by vbandha

The tunnel interface IP is used for the traffic originating from fortigate itself to travel on the tunnel.
Without that, this traffic would use the exit interface IP, which would be the WAN interface IP and it would not be able to go on the tunnel

The reason we do this in SD WAN is because fortigate is sending traffic for SLA or ping for checking if the link is still up
To allow all this traffic to go across the tunnel, we have to define tunnel interface IP and add it to the phase 2 selectors.

So now when Fortigate sends all this traffic on tunnel, it would use the tunnel interface IP.

Here are some articles which you can refer for more information:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Self-originating-traffic-over-IPSec-VPN-For/ta-p/193456
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IPsec-VPN-with-SD-WAN/ta-p/209840

1 reply

vbandha
Staff
vbandhaAnswer
Staff
March 15, 2023

The tunnel interface IP is used for the traffic originating from fortigate itself to travel on the tunnel.
Without that, this traffic would use the exit interface IP, which would be the WAN interface IP and it would not be able to go on the tunnel

The reason we do this in SD WAN is because fortigate is sending traffic for SLA or ping for checking if the link is still up
To allow all this traffic to go across the tunnel, we have to define tunnel interface IP and add it to the phase 2 selectors.

So now when Fortigate sends all this traffic on tunnel, it would use the tunnel interface IP.

Here are some articles which you can refer for more information:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Self-originating-traffic-over-IPSec-VPN-For/ta-p/193456
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-IPsec-VPN-with-SD-WAN/ta-p/209840