Skip to main content
oliverlag
New Member
September 1, 2015
Question

VIP over multiple interfaces

  • September 1, 2015
  • 5 replies
  • 11102 views

Hi, 

I'm trying to reach this:

I do have 2 IPSECs VPN over a customer. On the customer side I need to use some prenat and so I have some VIPs. 

Those VIPs are attached to the VPN interface.  That's a problem because I can't have fully redundance because of limit of the VIP attached to one single interface. (and I can't use interface any). 

I tried to ask to support and they suggested me to use soft / hardware switch and make a single logical interface with the two VPNs. Unluckily this is not possible. 

I tried to workaround this using loopback interfaces and gre tunnels but it does not work (VIP object can't be linked to loopbacks or gre or zones). 

Someone has some suggestion about how to workaround this (if it's possible)? 

 

Thanks

    5 replies

    N_Shagar
    New Member
    February 15, 2018

    I have the same problem, if I set interface as any, the local address(mapped) lost your access to Internet, but I need to send traffic between 2 specific interfaces, but Fortigate let me set only 1.

    @oliverlag, does you has been succeeded?

     

    CHgeek
    New Member
    April 24, 2018

    Ho oliverlag,

     

    I have the exact same problem. What was your solution to it?

     

    Kind regards,

    CHgeek

    emnoc
    New Member
    April 24, 2018

    Do you have a topology map? You could in fact make a  DNAT vip for ipsec and should be able to  define the VIP as any.

     

    Ken

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!