Created on
‎05-23-2024
09:21 AM
Edited on
‎01-09-2025
02:00 AM
By
Jean-Philippe_P
Description | This article describes the steps to set up an SD-WAN dial-up VPN using BGP routing. |
Scope | FortiGate. |
Solution |
This article will explain and show the configuration example for Dial-UP IPSec VPN in the SD-WAN scenario. To understand the site-to-site IPSec VPN in an SDWAN scenario with a configuration example the following article can be reviewed: Technical Tip: Configure IPsec VPN with SD-WAN.
In this example, Port1 is used for DialupServer1(Primary) and Port5 is used for DialupServer2 (Secondary). A similar setup is configured for DialupClient.
In this example, DialupServer is 10.185.0.0/20 and DialupClient is 10.162.0.0/20.
Below are the configuration steps:
The output should be as below:
DialupClient1 and DialupClient2 should be similar:
Dial-up Client:
The local address group includes the local network, DialupServer1 & 2 tunnel IP (with mask /32). The remote address group includes the remote network, DialupClient1 & 2 tunnel IP (with mask /32).
Configure the same on the DialupClient1 and DialupClient2 FortiGate VPNs.
Final output:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.