Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
WQ
New Contributor

can create remote-access ipsec vpn on a floating public IP address?

Hi, we need to config remote-access ipsec vpn on fortigate. can configure using a floating public IP address?

the routing for this floating IP is configured properly, should be routed to the firewall via internet and local internet router. Can someone please advise? thanks in advance! 

1 Solution
distillednetwork
Contributor III

Are you referring to a floating IP address in a cloud environment, or do you have a public IP address you can advertise out through two ISPs via BGP?  

 

If it is the latter, it maybe possible to create an IPSEC tunnel off of a loopback interface, then create a VIP that is the public IP address you advertise via BGP and mapped to the loopback.  Just keep in mind when using a loopback for ipsec you could lose NPU offloading.  You can check your device with this: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Information-about-IPsec-on-loopback-interf...

::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::

View solution in original post

::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
5 REPLIES 5
distillednetwork
Contributor III

Are you referring to a floating IP address in a cloud environment, or do you have a public IP address you can advertise out through two ISPs via BGP?  

 

If it is the latter, it maybe possible to create an IPSEC tunnel off of a loopback interface, then create a VIP that is the public IP address you advertise via BGP and mapped to the loopback.  Just keep in mind when using a loopback for ipsec you could lose NPU offloading.  You can check your device with this: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Information-about-IPsec-on-loopback-interf...

::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
WQ

Hi @distillednetwork , thank you so much for your advice. yes, we have public IP block which can be advertised to ISP. what is NPU?  what is the impact if losing NPU offloading? 

funkylicious

"jack of all trades, master of none"
WQ

Thanks @funkylicious @distillednetwork for your kind advice!

distillednetwork

as the article posted by @funkylicious it puts more processing on the CPU vs the NPU that can offload and speed up that processing.  Depending on the size of the appliance and the volume of traffic it may not be an issue.

::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors