- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IP address for ipsec tunnel
is there any limit on the IP address that I can used for ipsec site-to-site tunnels from fortinet firewall to 3rd party firewall like in AWS cloud.
currently we have site-to-site ipsec using 172.xx.xx.xx/16 as our MPLS network are all in the range 172.16.0.0 to 172.32.0.0/16.
Can we do IP subnet out of this range?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi yeowkm99,
I don't see any reason why you couldn't not subnet the range 172.x.x.x/16 for the IPSec tunnel.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there is no limit on the IP subnet range.
Make sure the quick mode selectors on both ends are same
Salon Raj Joshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
any issues if i create ipsec tunnels to 2 difference 3rd party using the same subnets?
eg 172.25.0.0/16 souce, 172.30.0.0/16 destination and 172.25.0.0/16 source, 172.28.0.0/16 destination both with difference WAN IP address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
there will be no issue.
else you can also use VIP, IP pool concept.
refer:-
Salon Raj Joshi
