Description |
This article describes how to use local-ID type IP addresses other than the IP addresses configured in the interface for IPSec VPN. |
Scope |
FortiGate 7.0 and above. |
Solution |
Starting FortiGate 7.0, it is possible now to set the local ID IP address that is not configured in the interface selected.
Local ID can be used in aggressive mode. It may have up to 63 characters that are used in regular expressions. Local ID is an extra piece of data delivered during phase 1 of negotiation; the remote side may be set up to check for a particular ID to permit connection.
From CLI:
config vpn ipsec phase1 set localid-type address set localid <IP address> end
Here, mention an IP address instead of reference x.x.x.x.
Related articles: FortiGate sends 'local id' in FQDN type when negotiating an IPSec tunnel with Cisco Use of PeerID and LocalID in IPsec VPN between two FortiGates |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.