Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tim5700
New Contributor

VPN between Fortigate (static IP) & Palo Alto (dynamic IP)

I would think the Fortigate needs to act like a VPN server and the Palo as a dialup user.  Just unsure how to go about it.

2 REPLIES 2
syordanov
Staff
Staff

Dear tim5700,

 

For this scenario where Fortigate has static IP address and Palo Alto has dynamic IP address, you can check the KB bellow :

 

Dialup VPN Configuration Between Two FortiGates  

 

 

In your case the Fortigate will be configured as Dialup Server and Palo Alto will act as a dialup client.

 

Best regards,

 

Fortinet

.
Yurisk
Valued Contributor

Never configured PA as a VPN client, so can't comment on that, but have you considered using some DDNS provider on the Palo-Alto side? Then you could set up regular VPN site-to-site on Fortigate using FQDN instead of the IP for remote peer (PA). 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Labels
Top Kudoed Authors