Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
begar
New Contributor

Site to site IPSEC

Hello there, im fairly new to Fortinet hardware so i figured i could ask this question in here: I've setup a site-to-site IPSEC tunnel, my problem is that one of the sites has DHCP on the WAN port. Meaning that if the FortiGate resets, it will get a new ip address and then the tunnel will go down.

 

How do i configure an IPSEC tunnel where one of the sites gets its WAN IP via DHCP?

 

Thanks in advance :)

1 Solution
sw2090
SuperUser
SuperUser

since you don't always want to reconfigure your IPSEC whan that WAN IP changes use some dyndns service to create a FQDN that resolves to that ip and make sure there is some client on the DHCP WAN Site that keeps the dyndns up to date. Then set your IPSEC to use an FQDN as remote gw and set it to the dyndns your created.

 

If the DHCP WAN Site is a FortiGate too you could easily use the built in fortiddns service on that FGT :)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

View solution in original post

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
2 REPLIES 2
sw2090
SuperUser
SuperUser

since you don't always want to reconfigure your IPSEC whan that WAN IP changes use some dyndns service to create a FQDN that resolves to that ip and make sure there is some client on the DHCP WAN Site that keeps the dyndns up to date. Then set your IPSEC to use an FQDN as remote gw and set it to the dyndns your created.

 

If the DHCP WAN Site is a FortiGate too you could easily use the built in fortiddns service on that FGT :)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
begar
New Contributor

Worked like a charm, thank you very much for you fast and accurate reply :)

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors