Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hianilz
New Contributor

can SSLVPN use more than one ISP? If primary goes down can user still connected through secondaryISP

Hey,

 

We got traformed from Sonics to Fortigates and have situation that we have two ISP's but  we had configured only one ISP for our SSLVPN. 

 

Looking for a solution where if my Primary ISP goes down would like use secondary ISP seamlless for SSLVPN users on user propsective 

 

Is there any way we can configure on FortiGates for this solution ?

2 REPLIES 2
hbac
Staff
Staff

Hi @hianilz,

 

Yes, you can use list both WAN interfaces to listen for VPN connections. You can also use DDNS to connect to the VPN instead of IP address. Please refer to the following links: 

 

https://community.fortinet.com/t5/FortiGate/Technical-Note-SSL-VPN-redundancy/ta-p/195760

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-Redundancy/ta-p/189668

https://community.fortinet.com/t5/FortiClient/Technical-Tip-Multiple-gateway-IP-for-FortiClient/ta-p...

 

Regards, 

akanibek
Staff
Staff

@hianilz,

I presume it is not possible, I have never had such experiences. Maybe my colleagues have another opinion - let's observe it together.

Since SSL-VPN is stateful, it can not seamlessly move to another ISP, Client will just terminate connection. If there is another option such like load-balancing for ssl.vpn virtual public interface - I don't think so (at least). 

Asset
Labels
Top Kudoed Authors