i am try ting to config 40F to 40F using site to site vpn when HQ has Static WAN ip and Branch use Dynamic , after config the tunnel is still down , even i try Hub - Spoke same issue , in HQ the 40F setup is behind the main Firewall ( 60F ) , does it required any Port forwarding . i have go through several video and documents , the config show ok ,still the VPN not coming online .
this would be kind of hard to implement if your IPsec Hub / DialUP server FGT is behind another FortiGate and doesnt have a public IP assigned to it.
one option would be to create VIP on the 60F for 40F , like the one described here - https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-a-FortiGate-in-the-middle-for-...
| User | Count |
|---|---|
| 2702 | |
| 1416 | |
| 810 | |
| 716 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.