Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AntonioTorresMiguez
New Contributor

How to get access to this post

Hello,

We have a problem with a client to create two VPN IPSEC DialUP.  How can I get access to the following post?

https://community.fortinet.com/t5/Internal-Knowledge-Base-Articles/Technical-Tip-Using-Peer-ID-to-co...

common.feature.saml.dev.post.page_title

 

 

Thank you.

AntonioTorres
AntonioTorres
1 Solution
ede_pfau
Esteemed Contributor III

Your link is internal, this probably is the published article:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-Peer-IDs-to-select-an-IPSec-dia...

 

and some background info about the selection process:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Dynamic-IPsec-VPN-Responder-Dialup-Selecti...

 

The trouble is, if you start to build a VPN infrastructure, you might overlook to introduce peer IDs with your first dialup tunnel. After all, it works without. Only later, when you need the second or more dialup tunnel, you will notice that sometimes the tunnel won't come up. But it may be too late to get a peer ID into your Forticlient configs...if not managed centrally.

 

One workaround might be (see second article) to use different proposals in phase1. They are part of the selection process.

And then use peer IDs for all upcoming new dialup tunnels.


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
3 REPLIES 3
ede_pfau
Esteemed Contributor III

Your link is internal, this probably is the published article:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-Peer-IDs-to-select-an-IPSec-dia...

 

and some background info about the selection process:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Dynamic-IPsec-VPN-Responder-Dialup-Selecti...

 

The trouble is, if you start to build a VPN infrastructure, you might overlook to introduce peer IDs with your first dialup tunnel. After all, it works without. Only later, when you need the second or more dialup tunnel, you will notice that sometimes the tunnel won't come up. But it may be too late to get a peer ID into your Forticlient configs...if not managed centrally.

 

One workaround might be (see second article) to use different proposals in phase1. They are part of the selection process.

And then use peer IDs for all upcoming new dialup tunnels.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
AntonioTorresMiguez

Thank you for your help, this was very useful.

AntonioTorres
AntonioTorres
alif
Staff
Staff
Labels
Top Kudoed Authors