- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SSLVPN on VRRP ip shared
hi all !
i've a question :
i've 2 FGT 200F cluster on different location connectet by several link that share the my own BGP pubblic IP access in VRRP.
so every cluster have different phisical IP on WAN interface and a COMON VRRP Address that i use to terminate IPSEC VPN declaring the Local Gateway ip address.
In case of Failiure of the Primary location the Ipsec VPN tunnel will be closed on the same VRRP address on other location.
Is it possible to use same configuration for SSLVPN?
In gui i have not found the possibility to specify the IP where the sslvpn listen to,
but only The INTERFACE where the services in Listen on - there are some other workarround?
I'm in 7.0.12 Nat mode
Thanks Alberto
Solved! Go to Solution.
- Labels:
-
FortiClient
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @AlbertoMantovani ,
In both scenario, its completely depends upon the upstream how forwarding happen towards firewall.
Basically I can say, you can try with it.
However as per lab behavior , for VRRP IP its not listening to SSLVPN interface.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ciao Alberto,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @AlbertoMantovani ,
As I have understand you are trying to add VRRP virtual interface ip address into SSLVPN listening interface, If I am wrong please correct me.
I have tested this in my LAB setup, however it didn't work, traffic for sslvpn port was getting drop in fortigate. However vrrp virtual ip address is responding to fortigate https traffic.
I believe there is certain limitation where firewall SSLVPN interface is not listening to vrrp ip address.
You can consider different approach to achieve this either by creating loopback interface.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, my issue has been fixed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First of all - Thanks for your time! i enjoyed it
I will study the possibility of using the loopback interface for ssl-vpn
My goal is to use the same IP address
in shared VRRP for 2 FWs (located in different datacenters)
I suppose the VIP solution doesn't work, because if I try to configure
the same VIP on 2 different Firewalls connected with L2 links
I think I could crash in an IP Conflict
What do you think about it?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @AlbertoMantovani ,
In both scenario, its completely depends upon the upstream how forwarding happen towards firewall.
Basically I can say, you can try with it.
However as per lab behavior , for VRRP IP its not listening to SSLVPN interface.
Thanks,
