Hey all, I've got a location with fortigate/ipsec site to site VPN; i.e. branch to HQ. There is a user on wifi at branch, where wifi only has internet access. Internet access from wifi leaves the local fortigate via the same interface the site to site vpn traffic uses, and that user would like to VPN to HQ.
Is there some combination of IPSec settings that will allow the site to site VPN and "dialup" users to connect to the same target Fortigate from the same source WAN IP? I've attempted aggressive mode IKEv1 with a variety of combinations of peertype any vs one, unspecified, and then either phase 1 local id set or not set, etc. but have not arrived at a combo that allows both to exist in harmony.
you need to limit the dial up tunnel to a specific peer-id. Otherwise the FGT cannot determine the correct tunnel and gets messed up ;)
Works fine here this way.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1738 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.