Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
needhelp22
New Contributor

Establish multiple IPsec VPN via single WAN on FG

Hi all, I'm planning to do SDWAN with my current setup, but I've to admit that my setup might not be optimal. Currently the setup is, LAN --- HQ FG --(Single WAN)-- LB (3 WANs) -- Internet -- (Single WAN) -- Branch FG.

My plan, was to build 3 IPsec VPN tunnels, and implement SDWAN over it. So the best performance tunnel will be selected automatically. I tried a few methods but I failed,

1. Secondary IP with different segment on HQ FG, configure Port Forward (or VIP) on LB, each WAN maps to one specific IP.

2. Loopback interface with different segment on HQ FG, configure Port Forward (or VIP) on LB, each WAN maps to one specific IP.

3. Peer ID, Local ID.

4. Network-overlag, network-id.

 

I'd like to seek for help on how can I achieve my plan with SDWAN. Appreciate any help, and thanks in advance!

2 REPLIES 2
Stephen_G
Moderator
Moderator

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen - Fortinet Community Team
Anthony_E
Community Manager
Community Manager

Hello,

 

I will answer to the question: how to establish multiple IPsec VPN tunnels via a single WAN interface on FortiGate, you can follow these steps:

  1. Configure the Phase 1 settings for each VPN tunnel:  Navigate to VPN -> IPsec -> Phase1 Interfaces. - Create a new Phase 1 configuration for each VPN tunnel. - Specify the necessary parameters such as interface, encryption algorithms, DH group, key lifetime, peer type, remote gateway, and pre-shared key.
  2. Configure the Phase 2 settings for each VPN tunnel:  Navigate to VPN -> IPsec -> Phase2 Interfaces. - Create a new Phase 2 configuration for each VPN tunnel. - Set the appropriate parameters like the Phase 1 name, encryption algorithms, DH group, and key lifetime.
  3. Configure the WAN interface settings:  Go to Network -> Interfaces. - Edit the WAN interface that will be used for the VPN tunnels. - Set the IP address and other necessary configurations for the WAN interface.
  4. Ensure proper routing:  Configure routing to direct traffic for each VPN tunnel through the WAN interface.
Anthony-Fortinet Community Team.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors