is there any limit on the IP address that I can used for ipsec site-to-site tunnels from fortinet firewall to 3rd party firewall like in AWS cloud.
currently we have site-to-site ipsec using 172.xx.xx.xx/16 as our MPLS network are all in the range 172.16.0.0 to 172.32.0.0/16.
Can we do IP subnet out of this range?
Hi yeowkm99,
I don't see any reason why you couldn't not subnet the range 172.x.x.x/16 for the IPSec tunnel.
Hi there is no limit on the IP subnet range.
Make sure the quick mode selectors on both ends are same
any issues if i create ipsec tunnels to 2 difference 3rd party using the same subnets?
eg 172.25.0.0/16 souce, 172.30.0.0/16 destination and 172.25.0.0/16 source, 172.28.0.0/16 destination both with difference WAN IP address.
Hi,
there will be no issue.
else you can also use VIP, IP pool concept.
refer:-
User | Count |
---|---|
1923 | |
1144 | |
769 | |
447 | |
279 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.