Created on
06-27-2025
12:49 AM
Edited on
07-28-2025
12:48 AM
By
Anthony_E
Description | This article describes the importance of using a static IP address, Fully Qualified Domain Name (FQDN), or Dynamic Domain Name System (DDNS) when configuring IPsec dial-in Virtual Private Network (VPN) tunnels on FortiGate devices. |
Scope | FortiGate, FortiOS v7.2.x and above. |
Solution |
When configuring IPsec dial-in VPN tunnels, it is critical to define a consistent and predictable remote gateway identifier to ensure reliable tunnel establishment and correct policy mapping. Using a dynamic IP address without DDNS or FQDN may result in negotiation failures, security policy mismatches, or unstable connectivity.
Key considerations:
Configuration Best Practices:
Example CLI Configuration:
Additional Recommendations:
Related documents: Technical Tip: Troubleshooting IPsec dial-up VPN connections |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.