Hi Everyone, I would like to seek an advice if is it possible to create 2 IP Sec VPN tunnel on fortigate firewall with 1 WAN interface ? if so is there any link or documentation that I can refer how to do so ?
I attached some topology for better understanding on this thing.
Solved! Go to Solution.
Issue solved...turn out to be some mismatch configuration on the preshared key..when I key in the preshared key again and the tunnel established..thank for helping
Hello,
Thank you for your question. Yes, it is completely possible. There is really nothing special from configuration pov. On left FortiGate, you will create 2 ipsec tunnels each for different wan link. The remote-gw will be 30.30.30.1. And on the right FortiGate, you will configure also 2 ipsec tunnels, both bounded to the same wan interface, one tunnel will have remote-gw 10.20.20.1 and second tunnel will have 10.30.30.1. And that's it.
Link to standard ipsec tunnel guide:
Hi akristof,
just now I just configure my fortigate with 2 different IP Sec tunnel to the same WAN port however I discovered that 1st VPN Tunnel is able to up and 2nd VPN Tunnel is down. Both side configuration is the same. I check on the events VPN log and discovered the "Action delete_phase1_sa". Is there anything that I need to check further ?
Hi.
Can you share phase1 configs of tunnels from both devices?
Hi akristof,
I did this testing with Ali Baba Cloud (ABCloud) to established the IP Sec VPN, however the concept is the same which is ABCloud with 2 WAN port interface established connection to Fortigate 1 WAN port interface. you may refer to configuration on both devices.
Issue solved...turn out to be some mismatch configuration on the preshared key..when I key in the preshared key again and the tunnel established..thank for helping
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.