Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Coldfirex
New Contributor

Site to Site VPN and not use main WAN IP?

Howdy, Is it possible to setup a site to site IPSEC tunnel on a different IP than is assigned to my wan port? I have a range of public IPs routed to it and would prefer to use an unused one if possible. Thanks! FGT100D running v5.0.6
6 REPLIES 6
emnoc
Esteemed Contributor III

I don' t think that' s possible,and why would you want to do that? What you could do; is plumb the ip_address to a virtual interface like a loopback and terminate the VPN to that address But once again; " I don' t see any advanatges as to why and you would gain absolutely nothing and waste a ip_address on the loopback" . Do you have a specific need to use another address for the VPN?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Coldfirex
New Contributor

Thanks. It was mostly due to convenience. I am putting in a FGT for a business that had split their connection (via a switch) to 2 different firewalls and all of their S2S vpns were going to a device that was using not using their main public ip. I will more than likely just end up updating all of the other devices for the main IP.
emnoc
Esteemed Contributor III

Ah I see.... now Try the loopback address and see if that would work in your environment. That might be the best thing. Moving site2site vpns between firewalls is a challenge when you trying to contact the remote-site and re_address the ip_address and/or PSK. I had a similar problem like 1 year ago with moving over 60 plus vpns and trying to get 20 different parties to make address changes. It was a disaster to say the least. Some of my vpns stayed down for like 2 weeks due to contacts and vendors not working effective. I really wished I had stacked a loopback interface or maybe NAT my source_address on my edge-router using a policy-based nat rule to steer traffic udp500 and ESP to my backend address.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
brianmac64
New Contributor

the ' remote-gw' setting in phase1-interface config for the specific tunnel and set the desired ip. you will also have to add that ip as a secondary to the incoming interface. also, it seems that the secondary ip needs a 32 bit mask to be entered...
moo?
moo?
ChrisM

Glad I found your above comment. Been looking at trying to get this to work for the last two days!

emnoc
Esteemed Contributor III

the ' remote-gw' setting in phase1-interface config for the specific tunnel a
I think you meant local-gw . Remote-gw is just that, the remote address.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors