Hello there, im fairly new to Fortinet hardware so i figured i could ask this question in here: I've setup a site-to-site IPSEC tunnel, my problem is that one of the sites has DHCP on the WAN port. Meaning that if the FortiGate resets, it will get a new ip address and then the tunnel will go down.
How do i configure an IPSEC tunnel where one of the sites gets its WAN IP via DHCP?
Thanks in advance :)
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
since you don't always want to reconfigure your IPSEC whan that WAN IP changes use some dyndns service to create a FQDN that resolves to that ip and make sure there is some client on the DHCP WAN Site that keeps the dyndns up to date. Then set your IPSEC to use an FQDN as remote gw and set it to the dyndns your created.
If the DHCP WAN Site is a FortiGate too you could easily use the built in fortiddns service on that FGT :)
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
since you don't always want to reconfigure your IPSEC whan that WAN IP changes use some dyndns service to create a FQDN that resolves to that ip and make sure there is some client on the DHCP WAN Site that keeps the dyndns up to date. Then set your IPSEC to use an FQDN as remote gw and set it to the dyndns your created.
If the DHCP WAN Site is a FortiGate too you could easily use the built in fortiddns service on that FGT :)
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Worked like a charm, thank you very much for you fast and accurate reply :)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1633 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.