Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
astuk
New Contributor

SSLVPN using Virtual IP to Connect to Multiple internal IP

i have IPSec VPN tunnel where al Phase 1 and 2 done and VPN tunnel is up.
i configure phase 2 IP with virtual IP and i mapped it to an internal IP, now tunnel is up and my internal server is able to reach remote site.

Now it come as business need, we need multiple servers to reach remote site and they are in different subnet. how to reconfigure this virtual IP to map to diffrent intenal IP in diffrent subnet.

10.0.0.0.1 192.168.1.254
2 REPLIES 2
xshkurti
Staff
Staff

@astuk 
You have to create different virtual IPs, each of them mapping to different server.
All these virtual IPs need to be added to phase2 selectors of IPSec VPN on both ends.

TuncayBAS
Contributor II

I don't know your exact structure, but you may need to open VIP for each server.

Or you can use the IP range in the VIP definition.
For example :
172.16.16.1-172.16.16.254 in the "External IP address/range" field
192.168.2.1-192.168.2.254 in the "Map to IPv4 address/range" field

By using it, local servers can access the remote location by entering VPN and changing to their own nat ip.

This way, you will not have to define VIP separately for each server.

Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors