Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aminbaikuae
New Contributor

site to site with private ip problem

Hello, 

i have two branches, the main branch has FortiGate 60f and the second branch have FortiGate 40f 

the second branch does not have a static IP and we cannot control the port forwarding. 

the main branch has a static IP.

any way to configure site to site?

thanks.

3 REPLIES 3
sw2090
Honored Contributor

unfortunately there is an issue with site2site and dyndns.A site2site vpn always needs both "ends" to be defined. Since one Side does not have a static wan IP and you do not want to always change the ip manually you would need to use some dyndns service. Unfortunately inside VPN FortiOS fails to update the remote gw ip even though the dyndns itself works properly.  This always results in the vpn going down once the ip changes for first time. 

I already discussed this with TAC but there is still no fix or solution.

The only workaround would be to use I dial up vpn instead since this only requires the "end" that is dialled into to be defined.

Once can still route everything through a dial up aswell. I just don't think that on FGT you could use MFA for vpn auth.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
hbac
Staff
Staff

Hi @aminbaikuae

 

You can configure dialup VPN where 40f is the dialup client. Please refer to https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/6896/fortigate-as-dialup-cli...

 

Regards,

mle2802
Staff
Staff

Hi @aminbaikuae,

You may want to try to configure 60F with Dial-up VPN and 40F with site-site template so on 60F, we always listen for the request from 40 and did not need a remote gateway. Please refer to this document for more detail "https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/6896/fortigate-as-dialup-cli...

Regatds,
Minh

Labels
Top Kudoed Authors