The scenario I am trying to configure is pretty simple. I have FGT300E (v6.2.1) as a vpn headend and multiple other devices which would act as remote sites. Since the remote sites could have a NATtd WAN ip, I believe the dial-up vpn config on my headend is the best way to do this. This way I also do not need to make any changes on my headend as new remote sites join. However what I have seen is that when I have multiple clients connecting, the tunnel goes down on the previous one before connecting to the new one. I tried using 'set add-route disable' which bring up all tunnels, but from the headend side I can only reach the 1st remote site. Traceroute shows that all packets to the remote sites get routed to the initial remote tunnels virtual interface (instead of each sites virtual interface). I have unique peer-ids, keepalives, auto negotiates etc enabled too.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1643 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.