| Description |
This article provides a setup where there is a dial-up server and multiple dial-up clients. In the given setup, upon the first dial-up client being connected, and when the second dial-up client tries to connect, the first dial-up client goes down. |
| Scope | FortiGate Dialup IPSec. |
| Solution |
Below is a basic configuration of the Dialup server and Dialup client.
HUB:
config vpn ipsec phase1-interface edit "HUB" Next
Spokes:
config vpn ipsec phase1-interface next
In the above setup, after successful connection of spoke-1 and when spoke-2 try to connect, spoke-1 goes down, making it possible to connect only for one spoke at a given time.
The reason for this is that in the HUB end, the default behavior is 'set add-route enable'. This will automatically add a route to the first spoke once it is established. When the second spoke tries to connect, the route will change to the second one, making the first spoke down, or keep the first route available, making spoke-2 not able to connect.
The solution for this is to disable 'set add-route'.
config vpn ipsec phase1-interface
Note: Refer to this KB article Technical Tip: Use of PeerID and LocalID in IPsec VPN between two FortiGates to set up Dialup server dialup client IPsec tunnel. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.