Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

VPN over PPPoE connection

Hello, I have a problem, for which I cannot find an easy answer: I have a FWF50B with PPPoE connection on wan1. I have set up IPSec tunnel for client-to-site connection. I also set up my FortiClient to connect to VPN remotely. Nothing ambiguous so far. It works just fine. Still, I have some problems with power loss on my FG (because of the power supplier - provider), and every time the box reboots, it receives a different IP from the Internet provider. This way I cannot connect with my FortiClient remotely, because I don' t know the gateway IP anymore. Can someone help me find out a solution to this problem? (one which doesn' t include aquiring an APC or something else) I am running v4.0 MR1 patch1. Thank you.
6 REPLIES 6
rwpatterson
Valued Contributor III

Set up Dynamic DNS on the interface. This will let you use a domain name that will follow the IP address changes.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Hello, exactly this I have done, after some research. I will explain the steps I have followed, in order for others not to waste too much time with digging into this issue. I don' t have a registered domain, so I used a free one from www.dyndns.org. I have created an account and a host under the domains supported by the DDNS client in Fortigate. After this, I configured the FG by enabling DDNS option under wan1 interface and completing the empty fields with the information from dyndns account (domain, server, username and pass). This way, every time the IP will change, the DDNS client in FG will connect to dyndns.com and update the host information with the new IP.
rwpatterson
Valued Contributor III

Exactly. Well done.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

I have another question regarding this topic: I am using a VIP. Still, as you know, to create it, I had to use external IP, which again brings us at the same problem: if my IP is changing every time, I cannot access the VIP anymore.
rwpatterson
Valued Contributor III

Change the outside IP to the wildcard (0.0.0.0). This will cover all IP addresses there. Be careful if you do not use port forwarding, as this will prevent you from managing the device from the outside.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Thank you, that worked. I am using port forwarding, so remote management should not be a problem.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors