Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
carl_webster
New Contributor

Dual Gateway and VPN

Hi,

 

I have 2 broadband connections coming into one site, one BT which does DHCP for the site devices.

I also have a Virgin connection which is currently unused.

 

I have setup a Fortigate 70D to the Virgin Hub and have a valid connection to the internet (to a single laptop)

My intention is to add this to the network so our SA office can dial in.

What is the best way to go about this please?

2 REPLIES 2
sw2090
Honored Contributor

Well as a VPN does need at least one defined "end" (the remote Gateway that is) you cannot practically do vpn over wllb. 

We do like this here: we use two IPSec Tunnels the FortiGate at the shop (if they have two wan) and do priority based routing to select one. This will give you some fallback then (redundant Site2Site IPSec that is).

 

You could also do that with a FortiClient or whatever dial up vpn however in this case you cannot to automatic fallback (unless the vpn client you use supports that). Prio based routing over them dial up vpns does btw not make sense since you cannot dial into more then one vpn the same time (i.e. if you do and have the same remote subnet this will overwrite your route so the other connection gets useless).

 

However since I didn't yet use anything else I cannot give you a recommendation wether this is the best way or net. It's bascially one way to do it ;)

 

Cheers

Sebastian

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

WHat popped to my mind is something lilke dyndns since you can enter a FQDN as remote gw on a FortiGate VPN or in FortiClient. HOwever this would require a rather complex dyndns setting (i.e. when to update DNS with which ip) and I am not sure if FortiOS/FortiClient or any dyndns client supports this...

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors