multiple ipsec dialup tunnels, for each interface would be necessary i guess.
I would like not to do multiple ipsec dialup tunnels. any best practice solutions ?
Haven't tested and don't have time to test before my vacation, but an idea is to set two VIPs from both interfaces to forward IPsecs(UDP 500/4500) to a loopback interface, and make sure the policy doesn't block ESP. Again, just an idea.
Toshi
Seems like a good solution Toshi thank you.
I will look in the internet how to do the ESP you are talking about.
Whenever you or anybody can, can you test in the fortigate 7.6.3 version (or latest) ? thank you
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.