Hello, I have an FG60F in the HQ with dual WAN. WAN1 distance 5 and WAN2 distance 10. Is it possible to set up an IPsec VPN over WAN2 to a branch office without SDWAN?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
yes it is. In IPSec you can either use SDWAN-VPN if you want it to be redundant or you can still do without SDWAN and use the wan on its own for a tunnel (and do redundancy by routing priority).
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
I tried that. I can only set up a tunnel if WAN2 has a shorter distance than wan1. This means that all internet traffic from HQ goes over WAN2. I have already experimented with static routes, administrative distance and priority. Doesn't work. Are there any instructions on how to do this?
hm strange.
Internet traffic will use the route that SDWAN chooses accoarding to the matching sdwan rule.
However you tie an IPSec to an interface so it will use that interface to talk to the remote gw. It definitly does do that here.
Traffic will then use the IPSec (once established) if it matches any static route over the IPSec.
I always had to IPSec S2S tunnels per site over two different WANs and the routing prio in the static routes for the site subnets gave which IPSec had to be used. So it primarily used the matching route with lowest prio and if that one was down it used the other.
Meanwhile I'm using SDWAN-VPN for this.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1679 | |
1085 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.