Dear friends,
Regarding the KBs below:
I understand that to use an IP address not other than the primary IP address configured on the exit interface of the tunnel, the IP address should be configured as a secondary IP address on that interface.
Technical Tip: How to configure IPsec VPN settings... - Fortinet Community
Why the option "specify" is still existing as an option to configure the local gateway IP address of the IPSEC tunnel.
I tested the "specify" option and the tunnel did not come up until I configured my IP as a secondary IP.
So what cases I should use the specify option? shall it be an IP address that is configured on another interface?
Solved! Go to Solution.
There is no difference in CLI.
Both options are doing the same thing, will configure the local gw IP. The GUI is just giving you the option to enter your IP manually or select it from the secondary IP list.
There is no difference in CLI.
Both options are doing the same thing, will configure the local gw IP. The GUI is just giving you the option to enter your IP manually or select it from the secondary IP list.
Say, you have configured 2 public addresses on your WAN port, one regular and one as a secondary address. By specifying the secondary as "local gateway" in one of your ipsec phase1 setups, you make the ipsec process listen to that address (and eventually process the tunnel creation).
Without "local gateway", you specify "wan" as the external port in your phase1, but FortiOS will only serve IKE requests on the "wan" address - not any secondary. So this goes hand in hand if using multiple addresses on a port.
Of course, you can terminate multiple VPNs on the "wan" port on multiple public addresses this way, if you need to.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.