Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

best practice tunnel ip interface ip assignment

Hi Fellas, I have 1 HQ and 20 remote sites. HQ configured as DialUp VPN Server through OSPF. searching the web and forum doesn't give relative info best practice/recommended VTI  ip assignment.

 

Which is appropriate setup

For HQ I assigned IP:192.168.1.1 Netmask:/32 Remote IP/Netmask: 192.168.1.2/24

or 

For HQ I assigned IP:192.168.1.1 Netmask:/32 Remote IP/Netmask: 192.168.1.2/30

 

Branch VTI

I assigned IP:192.168.1.3 Netmask:/32 Remote IP/Netmask: 192.168.1.1/24

or

I assigned IP:192.168.1.3 Netmask:/32 Remote IP/Netmask: 192.168.1.1/30

 

 Can it ruin my setup if assign already an assigned ip address to other branches? Branch 2 local ip 192.168.1.10 and Branch 10 will use same ip address 192.168.1.10 as local ip?

 

Fortigate Newbie

Fortigate Newbie
0 REPLIES 0
Labels
Top Kudoed Authors