Created on
‎04-08-2022
05:10 AM
Edited on
‎08-25-2025
01:13 AM
By
Jean-Philippe_P
Description |
This article describes how to use local-ID type IP addresses other than the IP addresses configured in the interface for IPsec VPN. |
Scope |
FortiGate v7.0 and above. |
Solution |
Starting FortiGate v7.0, it is now possible to set the local ID IP address that is not configured in the selected interface.
Local ID can be used in aggressive mode. It may have up to 63 characters that are used in regular expressions.
Local ID is an extra piece of data delivered during phase 1 of negotiation; the remote side may be set up to check for a particular ID to permit connection.
From CLI:
config vpn ipsec phase1-interface edit <phase1_name> set localid-type address set localid <IP address> end
Note: The 'localid-type' is only configurable via CLI. This option is not available in the GUI.
It mentions an IP address instead of the reference x.x.x.x.
Related articles: Technical Tip: Use of PeerID and LocalID in IPsec VPN between two FortiGates |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.