Skip to main content
Deftone
New Member
February 18, 2020
Solved

WAN and failover dialup IPSec

  • February 18, 2020
  • 7 replies
  • 5139 views

Hi everyone,

 

I think I need some help. I will try to explain what I'm trying to achieve.

 

We have a headquarter and three small locations. In our headquarter we have a big FG1500 and on the three small locations we have FGT30E 3G/4G. The locations are connected through eternity circuit and and running OSPF between.

 

On the small locations I configured dial up IPsec through LTE to our main Fortigate with OSPF.

Everything is working fine on sub locations while connected to the ethernet circuit. I learn routes through OSPF as expected and can reach everything.... The default route is learnd from the headquarter Fortigate and that's fine....

 

When I disconnect the ethernet circuit the IPSec kicks in and the routes are learnd through the IPSec interface except the default route... Instead of learning my default route form the main Fortigate the default route from the LTE is injected in to the routing table with a distance of 10 I tried to change the distance under the LTE interface but then my IPSec goes down...

 

Someone any idea how I can fix that... What I'm trying to achieve is that the small Fortigate learns the same subnets and default gateway from the main Fortigate on the IPSec as when connected through ethernet circuit

 

Thanks 

    Best answer by Toshi_Esumi

    You need to have a /32 static route for the HQ's IP toward the LTE interface to keep the tunnel up. Then you can change the distance higher than OSPF (110).

    7 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    February 18, 2020

    You need to have a /32 static route for the HQ's IP toward the LTE interface to keep the tunnel up. Then you can change the distance higher than OSPF (110).

    Deftone
    DeftoneAuthor
    New Member
    February 18, 2020

    Hi,

     

    Thanks for the reply...

    Just wondering... Should I create static route to the WAN ip of the HQ towards the IPSec tunnel interface or the wwan interface for LTE

     

    For the tunnel interface it would looks like this: 

     

    config router static

        edit 0

            set dst 192.168.30.100 255.255.255.255

            set device “TUNNEL_INTERFACE" 

        next

    end

    Toshi_Esumi
    SuperUser
    SuperUser
    February 18, 2020

    LTE. That's where the injected default route was pointing to, right? Which would go away when you change the distance.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!