Created on
06-20-2024
10:30 PM
Edited on
02-10-2025
01:58 AM
By
Jean-Philippe_P
Description |
This article describes the difference between the number of supported client-to-gateway IPsec VPN tunnels and gateway-to-gateway IPsec VPN tunnels specified in the FortiGate datasheet. |
Scope | FortiGate. |
Solution |
For every FortiGate on top of the IPsec VPN throughput, maximum values of supported client-to-gateway (also referred to as remote access) IPsec VPN tunnels and gateway-to-gateway (also referred to as site-to-site) IPsec VPN tunnels are published in the datasheet.
IPsec throughput specified can be used for creating gateway-to-gateway (site-to-site) or client-to-gateway (remote access) IPsec VPN tunnels or the combination of both up to the maximum throughput and tunnel quantities specified. These numbers are often different based on the example shown below:
The difference lies in the way these two IPsec VPN tunnel modes are configured. The number of gateway-to-gateway (site-to-site) IPsec VPN tunnels is capped by the number of phase1 configurations that can be created for various FortiGates.
For phase1 interface quantity, there is a table size limit for every FortiGate ('config vpn ipsec phase1' for policy-based configs, or the max number of logical interfaces allowed for route-based configs).
Expanding this into Fortinet SD-WAN topology perspective, gateway-to-gateway, and client-to-gateway IPsec VPN tunnels can be associated with the various configurations in the SD-WAN topology:
|