Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
imrankatela
New Contributor

Help with IPSec VPN after migrating to the ISP link to SD-WAN.

Hey folks,
I ran into a problem after migrating my WAN interface into SD-WAN because I wanted to add a secondary ISP connection. I know I should have added my ISP link to SD-WAN from the beginning but that's for another day. My Site to Site VPN get disconnected when I enable the 2nd ISP link, it goes back to UP when I disable the link. I've already raised a TAC ticket but it's so slow.
I've added an SD-wan rule to the remote peer IP to go though the ISP1 (Which is the VPN interface). But issue is still here.
While pcap on the ISP2, I found that ISP1's packets are being set though it. Also find VPN port 4500 being sent through that link too. My VPN setting are all same, with ISP1 as the listening interface.
I'd really appreciate any help from this community.

192.168.0.1 router login 192.168.l.l
2 REPLIES 2
gonelbo1
New Contributor

Wow, thanks for the fast reply! Just so happens that IP space is no problem - we happen to have two class C blocks (/20 & /22) that we bought WAAAAY back before NAT came along and we've held onto 'em since.

omegle xender
AEK
SuperUser
SuperUser

Hi Imran

Which FortiOS version?

Please share screenshot of phase 1 config and SD-WAN rules.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors