The scenario:
1. I have a web application installed on my server, which is on IP 192.168.31.68 and the application is accessible on local network through link https://192.168.31.68/U_GEAR.
2. I have FotiGate 40F firewall who WAN is connected to Internet (as well as on company LAN basically) and has IP 192.168.31.193.
3. I do not have a static IP.
I want to access this web application (which is an ERP) on an external network. How can I achieve this using the current system? The constraint remains that cannot change the IP configuration of the Server or the other ports in the company.
Someone from the ERP team asked to use VPN and enter local network. However, I do not have any idea on how can this be achieved.
Using VPN is usually the best way here since there’s no static IP and the server setup can’t be changed. You can set up SSL VPN on the fortigate so remote users can securely connect to the local network and access the ERP through its local link. Port forwarding with Dynamic DNS could work too but that would expose the ERP to the internet, so vpn is definitely the safer option. And if you want to keep you files organized, you can use cx file manager app.
Hi Saurabh
I don't think is a good idea to publish your ERP on the internet. If the ERP is intended to be accessed by the company staff then the right thing to do is to make it accessible through VPN, or ZTNA.
If you go for VPN, since SSL VPN is now discarded by Fortinet, then you will need to configure dialup IPsec.
Regarding the dynamic public IP, you can use dynamic DNS, either for ZTNA or for dialup IPSec.
| User | Count | 
|---|---|
| 2727 | |
| 1417 | |
| 810 | |
| 738 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.