Hi, we need to config remote-access ipsec vpn on fortigate. can configure using a floating public IP address?
the routing for this floating IP is configured properly, should be routed to the firewall via internet and local internet router. Can someone please advise? thanks in advance!
Solved! Go to Solution.
Are you referring to a floating IP address in a cloud environment, or do you have a public IP address you can advertise out through two ISPs via BGP?
If it is the latter, it maybe possible to create an IPSEC tunnel off of a loopback interface, then create a VIP that is the public IP address you advertise via BGP and mapped to the loopback. Just keep in mind when using a loopback for ipsec you could lose NPU offloading. You can check your device with this: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Information-about-IPsec-on-loopback-interf...
Are you referring to a floating IP address in a cloud environment, or do you have a public IP address you can advertise out through two ISPs via BGP?
If it is the latter, it maybe possible to create an IPSEC tunnel off of a loopback interface, then create a VIP that is the public IP address you advertise via BGP and mapped to the loopback. Just keep in mind when using a loopback for ipsec you could lose NPU offloading. You can check your device with this: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Information-about-IPsec-on-loopback-interf...
Hi @distillednetwork , thank you so much for your advice. yes, we have public IP block which can be advertised to ISP. what is NPU? what is the impact if losing NPU offloading?
Thanks @funkylicious @distillednetwork for your kind advice!
as the article posted by @funkylicious it puts more processing on the CPU vs the NPU that can offload and speed up that processing. Depending on the size of the appliance and the volume of traffic it may not be an issue.
User | Count |
---|---|
2625 | |
1395 | |
810 | |
671 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.