Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
capricorn80
New Contributor II

VPN on Backup Internet Link

Hi!

My VPN is working fine on my primary link but due to some need I have to moved it to my backup link.

I have setup my backup link with AD of 20. I cannot ping that IP from outside. I can only see icmp request in the log.

The default route is set to my primary interface gateway so if I change the AD of Backup link to 10 then I lose connectivity to internet.

 So it looks like the backup link doesnt work even though I am setting the interface in my vpn to my backup internet and all the policies are pointing to it.

I only want to have L2tp running on my backup link.

 

How can I achieve this?

 

Thanks

4 REPLIES 4
capricorn80
New Contributor II

Update:

 

I have added the same AD for both route and then set priority of backup route to higher value. By this way I can have both route and I can see both routes in the routing table.

 

I was setting Policy based routing where my Wifi traffic is going via backup route and it works.

 

The issue now is that on policy based routing some of the traffic is not working. Like I cannot do SSL VPN from policy based route and L2tp as well. The browsing works fine. I will double check the rules and dig more.

I have set traffic type in Policy based routing to Any then I guess there should not be any blocking. Also I will rethink is there is more then something involved in this. that from backup link I cannot do ssl and l2tp vpn.

capricorn80

Anyone?

tanr
Valued Contributor II

A more complete network diagram and description would be helpful. 

 

I assume your backup route is going out a different public IP than your main route, correct?  What do you have the source-ip for your vpn set to?  Do you have static routes (with higher priority numbers) both directions?

capricorn80
New Contributor II

Hi!

 

I have two public IP terminated on port 15 and port 16.

Port 16 is backup connections.

My L2tp is listening on Port 15 and also I have ssl vpn on port 15

 

 

I have Guest Wireless network which normally goes out via port 15 but I configured this network to go out via port 16 because the idea was that L2tp will go out and come in with same network will not work. 

 

So I set Administrative distance on port 15 and port 16 as 10 and priority on port 15 as 0 and priority on port 16 as 50 so that port 15 will be the default route.

 

Then I configured policy based route so that wireless network will go ou via port 16 and it was working.

But VPN traffic i.e. SSL VPN and L2TP was not working.

 

I dont have diagram with this setup. The issue is if I can browse via Wireless network with my backup port 16 using policy based network then why I cannot use SSL VPN or L2TP with the same wireless network?

 

Thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors