I am trying to get a IPsec dialup VPN accessible from two interfaces WAN and LAN3.
Currently the IPSec VPN listens on WAN and that works well.
I have added a virtual ip on the LAN3 interface mapping from the public IP to WAN IP and created a firewall policy using this VIP.
With this in place the IPSec VPN will connect from LAN3 however no traffic flows across the tunnel.
Any idea what I am missing?
Hi s3,
Please verify with Policy (IPSEC to Lan), and IP POOL, if VIP is added on the multiple policies with outgoing 'Wan Interface'.
Check If the WAN interface is associated with VIP policy or not, then specify with IPSEC Interface instead of WAN Interface on IP POOL.
Confirm that there is a firewall policy allowing traffic from the LAN3 interface to the IPsec VPN.
Please refer to the document below and verify the details if the issue persists, please run the debug commands and share us the output for further analysis:
If you have found a solution, please like and accept it to make it easily accessible to others.
Regards,
Aman
User | Count |
---|---|
2588 | |
1380 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.