Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
johnlloyd_13
Contributor II

Update/Change VPN Tunnel Peer ID

hi,

i have a remote FW that i need to change to a new WAN public IP.

it currently has a ipsec VPN established using the old public/peer IP.

my question, can i change/update the remote IP address on the fly?

i checked it currently has a reference to the ipsec phase 2 tunnel config.

 

image.png

 

image.png

7 REPLIES 7
Toshi_Esumi
SuperUser
SuperUser

Is it from the same ISP on the same circuit? And both IPs/subnets are active on the ISP end?
If so, the ISP set the new subnet as the secondary IP on their end. Then you can do the same on your FGT to establish the tunnel on the new/secondary IP. Then eventually when it's safe, you can swap primary/secondary IPs, or just let the secondary override the primary IP.

Toshi

johnlloyd_13

hi,

same ISP, but instead of the public LAN range i'll use the WAN public IP instead.

dingjerry_FTNT

Hi @johnlloyd_13 ,

 

The phase2 is referencing the name of the phase1, not the remote IP.  So you can change the remote IP on the fly, either in GUI or in CLI..

Regards,

Jerry
dingjerry_FTNT

Actually, in the past, when I had issues bringing down the tunnel, I usually changed the remote IP in phase1, once down, I changed it back to bring it up again.

Regards,

Jerry
johnlloyd_13

hi,

thanks for the reply!

do i need to manually bring down the phase 1 VPN tunnel first before i change the remote peer IP in the VPN tunnel/phase 1 setting? then bring it up once new IP is applied?

 

Toshi_Esumi

@dingjerry_FTNTis saying he once used "changing remote IP in phase1" to "bring down the tunnel". You can just change the remote IP/remote-gw in phase1 config. FGT automatically flushes the existing tunnel when anything changed in the config.

Toshi

dingjerry_FTNT

Hi @johnlloyd_13 ,

 

No. In my case, I was troubleshooting with the original remote IP.

 

So what I meant is, you can change the remote IP directly.

Regards,

Jerry
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors