Created on
06-27-2025
12:49 AM
Edited on
02-25-2026
06:39 AM
By
Stephen_G
| Description | This article describes why a static public IP, FQDN, or DDNS hostname should be used as the remote gateway reference when configuring IPsec dial-in VPN tunnels on FortiGate. A stable identifier improves peer matching, strengthens security, and prevents tunnel instability when the remote peer’s public IP changes. |
| Scope | FortiGate, FortiOS v7.2.x and later. |
| Solution |
In IPsec dial-in deployments, FortiGate must reliably associate an incoming negotiation with the correct Phase 1 configuration. Using a predictable remote gateway reference (static IP / FQDN / DDNS) and an explicit peer identifier (when applicable) helps prevent negotiation failures, policy mismatches, and intermittent tunnel drops caused by changing ISP-assigned addresses. Why it matters:
Configuration best practices:
Example CLI configuration (dial-in / dynamic peer):
Additional recommendations:
Related documents |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.