Hello,
We have actually a wan1 connection with the interphace ip 80.xx.xx.xx (it's a private ip of our FAI named "SFR"). We have 5 VPN connection between our fortinet and other pfsense. All pfsense use the remote ip 80.xx.xx.xx of our fortinet. And also we have domain names that point to ports on our fortiner. For exemple test.mydomain.com:8080 point to 80.xx.xx.xx and a rules nat the port 8080 in a server behind the fortinet. Everything works fine.
But now we will install a backup internet connection on wan2 with a other FAI named "ORANGE" with the private ip 193.xx.xx.xx. For our users continue to use internet if wan1 is offline, i have to create a new sd-wan contains wan1 and wan2. This should work for the user continue to have internet transparently by wan2.
But for the VPN connection and the redirect port 8080 will it work ? Actually without sd-wan, the VPN is broken if wan1 80.xx.xx.xx is offline (it's normal). And we needs to have a backup link for if wan1 is offline, vpn can continue to work automatically with wan2. The sd-wan could keep the ip 80.xx.xx.xx.xx available if wan1 (80.xx.xx.xx) is offline and wan2 (193.xx.xx.xx) is online ?
I search how to keep the private ip online if wan1 or wan2 is offline.
Thank you for your help.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
For the ipsec vpn connections, you need to create a backup tunnel on the wan2. For SSL VPN connections your users need to use the IP address of the wan2 when wan1 is offline
Hi @erichard
For the test.mydomain.com:8080 NAT configuration, you may need to make sure the DNS record points to the backup internet when WAN1 is down. If you are using fortiDDNS service then the fortigate will automatically update the DNS record with active internet connection.If the DNS record is hosted on third party then you may need to check with them if there is any way to dynamically update the DNS record.
You can try to use loopback interface . Refer to the document
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1517 | |
1018 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.