Hi Tahhan
Sure you can. Your FortiGate with dynamic IP must be configured as dialup client.
Hope it helps.
Or, just use DDNS that FTNT/FGT offers.
Toshi
Created on ‎02-23-2025 12:43 PM Edited on ‎02-23-2025 12:51 PM
Hi Toshi
You are right, DDNS is more adapted to s2s while dialup FGT client is adapted for multiple FGTs with dynamic IP connecting to a hub FGT, right?
Edit : I know I need to review my NSE4 lessons.
Hello Tahhan,
Yes, you can configure a site-to-site VPN between two sites using a FortiGate 300E, even if one of the sites has a dynamic IP address. Here are the general steps to achieve this:
1. Set up Dynamic DNS (DDNS) on the FortiGate with the dynamic IP address:
- Ensure the DDNS service is functioning correctly on the FortiGate.
- Configure the FortiGate to use FortiDDNS with a unique location name corresponding to the WAN interface.
- For detailed steps on configuring Dynamic DNS on FortiGate, you can refer to the link provided in the configuration guide.
2. Navigate to VPN -> IPSec tunnels on the FortiGate:
- Create a new tunnel.
- For the remote gateway, choose 'Dynamic DNS' and input the remote site's DDNS name.
- Select the external interface (WAN) that will be used to communicate with the remote site.
By following these steps, you can establish a site-to-site VPN between the FortiGate 300E and a remote site with a dynamic IP address.
ref:
Regards!
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2656 | |
| 1410 | |
| 810 | |
| 699 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.