Created on 10-18-2004 12:00 AM Edited on 01-12-2025 11:04 PM By Anthony_E
Description
This article describes how to use Peer IDs to select an IPsec dial-up tunnel on a FortiGate configured with multiple dial-up tunnels.
Scope
FortiGate.
Solution
Dialup VPN tunnels are used when the remote VPN gateway or remote VPN client IP address is dynamic and therefore unknown.
Many customers use a single dialup tunnel (Phase 1 and Phase 2) for all remote dialup VPN gateways and clients.
Note: Multiple Peer IDs are used when only one wan interface is used for multiple IPsec connection
In some cases, multiple dial-up tunnels are required.
For example:
To grant different remote VPN client users access to different networks and services.
To grant remote VPN gateways access to different networks and services
FortiGates uses Peer IDs as the unique identifier to select a dialup tunnel. When multiple dialup tunnels are added, give each tunnel a different Peer ID.
Assign corresponding Peer IDs to remote VPN gateways and remote VPN clients.
To be able to add a Peer ID on an IPsec tunnel created by the wizard there are 2 options:
Note:
When the IPsec tunnel is created by the wizard, there is no GUI option to add a peer ID until convert the IPsec Tunnel to a custom tunnel.
Technical Tip: How to configure a FortiGate as IPsec VPN Dial-Up client when FortiGate is not behind...
Technical Tip: IPSec dial-up full tunnel with FortiClient
Technical Tip: FortiGate Hub with multiple IPSec Dial-up phase1 using IKEv2 and PSK authentication
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.