Am i correct in thinking that IPSEC site to site VPN configurations were the remote gateway is specified as a static IP, the tunnel will only be able to be brought up if the remote gateway is indeed on that IP?
What I am asking is can I depend on the fixed IP of the gateways being a 'factor' in 2 factor security. The other factor obviously is the pre-shared keys.
Thanks.
Answered my own question - IPSEC main mode uses the fixed remote IP to respond, thus can be a factor
:)
well the Fortigate does also support entering a FQDN as remote gw of an IPSec Tunnel.
I did that once using some dyndns fqdn since I have no static ip on that site and it works util today.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.