Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
s3
New Contributor

IPsec dial up VPN using virtual ip

I am trying to get a IPsec dialup VPN accessible from two interfaces WAN and LAN3.

 

Currently the IPSec VPN listens on WAN and that works well.

 

I have added a virtual ip on the LAN3 interface mapping from the public IP to WAN IP and created a firewall policy using this VIP. 

With this in place the IPSec VPN will connect from LAN3 however no traffic flows across the tunnel.

 

Any idea what I am missing?

1 REPLY 1
kaman
Staff
Staff

Hi s3,

Please verify with Policy (IPSEC to Lan), and IP POOL, if VIP is added on the multiple policies with outgoing 'Wan Interface'.

Check If the WAN interface is associated with VIP policy or not, then specify with IPSEC Interface instead of WAN Interface on IP POOL.

Confirm that there is a firewall policy allowing traffic from the LAN3 interface to the IPsec VPN.

Please refer to the document below and verify the details if the issue persists, please run the debug commands and share us the output for further analysis:

https://community.fortinet.com/t5/FortiGate/Setting-up-a-VIP-address-for-dialup-ipsec-VPN-between-Fo...


https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPSEC-Dial-up-VPN-over-VIP-to-access...


If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors