I am looking to get SNMP traffic to flow across an IPsec tunnel. I know I have to change the source ip in the CLI for this to work properly. My question is, I have been instructed to use a source IP from a local phase 2 selector. This is a route based tunnel so phase 2 is 0.0.0.0/0 on both sides. There is a static route for 0.0.0.0/0 to go out the WAN1 port for the IPsec tunnel. Would I be using the WAN1 interface ip for the source-ip in the CLI, or how would I go about making this change? Thank you.
Hi Show
Do you mean FortiGate as SNMP client? or you mean other equipment?
If WAN1 is a public IP then I don't think is a good idea. Try using your mgmt IP for example.
User | Count |
---|---|
2627 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.