Skip to main content
luckysantiago
New Member
July 11, 2018
Question

Use of secondary wan ip on ipsec vpn

  • July 11, 2018
  • 5 replies
  • 19478 views

Scenario:

wan ip: 1.1.1.1 (assuming 1.1.1.1 is public IP)

i have 1.1.1.2 as another public ip (same subnet of wan) that is whitelisted on the remote gateway of my client ipsec vpn.

how can i use 1.1.1.2 as outgoing ip address going to ipsec tunnel instead of wan ip 1.1.1.1 since on ipsec vpn config you can only select wan interface

 

so far i have tried both no good:

- set 1.1.1.2 as secondary ip of wan interface - create ip pool of 1.1.1.2 and use it on policy ipsec > lan, lan > ipsec

    5 replies

    navaraj
    New Member
    July 11, 2018

    Can any one help me out regarding how to make SSL VPN users to fail over with Back up (WAN 2)Link???

     

    Currently traffic is going via wan if wan1 fails internet trafiic gets switch over to Wan2.

     

    I Am having a problem of how to make SSL VPN users to connect on WAN 2 Ip..Even i added both public ips on VPN client system and checked .I can able to connect only with Wan 1 Ip

    rdumitrescu
    New Member
    July 11, 2018

    @luckysantiago, I assume that you are using route based Ipsec VPN.

    In this case if you need to use a secondary IP to establish a VPN connection you have to set the secondary IP as local gateway under phase 1 parameters:

    config vpn ipsec phase1-interface

    edit xx

    set local-gw 1.1.1.2

    end

     

    @navaraj, you need to add the interface wan2 under VPN SSL Settings

     

     

    luckysantiago
    New Member
    July 12, 2018

    That worked.  Thanks!

    Arpi73hu
    Explorer
    February 3, 2025

    Did you get an answer to this or find a solution? This is a question for me too

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!