I've been searching and searching on the best way to do this. I need to configure redundant dial in IPSEC VPN for FortiClient users. Meaning If WAN1's internet is down WAN2 will kick in and work Just like in an SD-WAN failover situation. I have not been able to find a clear answer on a config to do this. I know how to implement SD-WAN over IPSEC in a site to site config but there doesn't seem to be a clear config for dial in users using Forti Client. Any help is appreciated.
I passtrought the same demand here, maybe the best options is count with the free DDNS service from fortinet, created a DNS alias with booth WAN interface, of course this is free service and have some inconsistence, best shoot should be have a GSLB or any other Loadbalance capable to test if the circurt is UP and update the DNS automatically in case a wan failure
I'm about to test with free DDNS service from fortigate
| User | Count |
|---|---|
| 2838 | |
| 1436 | |
| 812 | |
| 796 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.