Skip to main content
Christian_89
Contributor III
July 3, 2022
Solved

VIP from Forti to Forti over WAN

  • July 3, 2022
  • 1 reply
  • 1173 views

Hello everyone

I have the following problem
On page A I have a Foritgate with incoming traffic.

Now the problem is the SRV's are on Fortigate side B.

There is another IPSEC tunnel between the two Fortigates.

How exactly do I have to configure the VIP there.

Many thanks for your help

Best answer by akristof

Hi.

If your topology is Client > Internet > FortiGateA > Ipsec > FortiGateB > Server then you have option to configure VIP on FGTA or FGTB. It depends on external IP address, if this IP is known to FGTA, for example its own public IP address, then configure VIP on this device. You also need to make sure that Ipsec tunnel has correct selectors configured.

1 reply

akristof
Staff
akristofAnswer
Staff
July 4, 2022

Hi.

If your topology is Client > Internet > FortiGateA > Ipsec > FortiGateB > Server then you have option to configure VIP on FGTA or FGTB. It depends on external IP address, if this IP is known to FGTA, for example its own public IP address, then configure VIP on this device. You also need to make sure that Ipsec tunnel has correct selectors configured.