Skip to main content
Yurisk
SuperUser
SuperUser
October 14, 2020
Question

VPN IPsec dialup peertype - how to use

  • October 14, 2020
  • 3 replies
  • 12233 views

Good day everyone,

I am trying to understand how and what for to use peertype dialup settings in Phase1 interface mode for IPSec VPN client connections. The documentation just lists this option, Google tells contradicting stories. I tried just for luck using Firewall group with local users  (setting via set usrgrp) - could not connect with any of them (Authentication failed), while using the same user group but peertype any works fine. 

 

That is what I mean:

(phase1-interface) # edit FCtun0

(FCtun0) # set peertype any Accept any peer ID. one Accept this peer ID. dialup Accept peer ID in dialup group.

 

Thanks.

3 replies

citromkolbasz
New Member
July 23, 2021

Have you found anything about this option in the official forti documentation? Or do you know the answer now?

sw2090
SuperUser
SuperUser
July 26, 2021

peertype any will accept any peer id you submit upon dialling in. It will even accept an empty peer id.

one peerid will only accept this one specific peer id upon dialling in. You will only be able to dial in if you submit the correct peer id.

 

dialup probably allows you to enter some grup and put peers in there to have more then one bt not any :)

sw2090
SuperUser
SuperUser
July 26, 2021

peertype any will accept any peer id you submit upon dialling in. It will even accept an empty peer id.

one peerid will only accept this one specific peer id upon dialling in. You will only be able to dial in if you submit the correct peer id.

 

dialup probably allows you to enter some grup and put peers in there to have more then one bt not any :)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!