Hi,
one of our customers asked us to configure a redundant Site-to-Site IPsec VPN with two static IPs or DNS-Names.
E.g. use IP/DNS name one to establish the tunnel, if this IP/DNS name is not available, establish the tunnel using IP/DNS name two. Is there a way to configure such a scenario using a FortiGate 100F with Firmware 6.0.8? Best Regards cust0m
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello and welcome to the forums In short, yes https://docs.fortinet.com/document/forticlient/6.0.6/administration-guide/247952/creating-redundant-...
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi,
I've solved it by simply creating two tunnels with two static IPs, two static routes with different distances and the dead pear detection feature that is enabled by default when creating a custom IPsec Site-to-Site VPN tunnel. helpful ressources:
https://www.youtube.com/watch?v=KUxhQaOwQuQ
[link]https://www.youtube.com/watch?v=xbyqfJdkB1U[/link] Best Regards cust0m
How many connection do you have in both sites? 2 - 2? To my point of view, the configuration is static, so, you don't need a DNS resolution. IPSec VPN is tipacaly used to site-to-site so, you only need to configuring the VPN failover ALG to keep always up the tunnel; use SD-WAN technology to create your priorities (based on customer's request). What you want is more useful for SSL VPN
Please think about updating FortiOS.
--
n
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1105 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.