Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ashik_Sheik
Contributor II

IPSec VPN 5.4.1 , site-to-site, dial-up User option is not working

Hi 

 

I am trying to setup Dailup user for site to site because in HUB i have Static IP and Branch have no IP .So can anyone help me to setup dailup for site to site to avoid going for Static and Dyndns for spoke .

 

Regds

 

Ashik

Sheik Mahammad Ashik
Sheik Mahammad Ashik
3 REPLIES 3
brycemd
Contributor II

I think what you are looking for is using Aggressive mode in the site to site rather than Main mode. This way you can do a proper ipsec site to site.

 

It allows you to configure the tunnel when one or both have dynamic IPs.(Page 48 in the document linked above)

MikePruett
Valued Contributor

I have configured this type of deployment in every version of FortiOS including 5.4.x without issue. Works like a champ

Mike Pruett Fortinet GURU | Fortinet Training Videos
Ashik_Sheik

Oh Great can you help me to configured .

 

My Queries

 

1. Head Office:when i choose dailup user, Preshared Key option is disabled .

2.Head Office :What to select Aggressive  or Main ID options

3.Branch - Static IP with Preshared Key is must to not 

4.Branch - Peer option Aggressive or Main ID 

 

Thanks 

 

Ashik

 

Sheik Mahammad Ashik
Sheik Mahammad Ashik
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors