Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
wadde
New Contributor

Two WAN IPs, one IPsec termination and one forwarding

Hi,

just want to know if this is possible.

Got a /29 from a provider on my WAN interface on the FortiGate. One IPsec tunnel should terminate on the Fortigate itself, the other one should be forwarded to another Layer 3 device behind the fortigate.

My plan would be:

- defining the main IP on the WAN interface and create the VPN Interface on WAN (IPsec terminating on Fortigate)
- definining a secondary IP address on the wan interface and create a VIP with that IP for UDP 4500 and 500 forwarding to the L3 device behind the fortigate (IPsec terminating on the L3 device).

Many thanks

router login 192.168.l.l
2 REPLIES 2
abarushka
Staff
Staff

Hello,

 

Both options are possible.

 

Secondary IP address can be used for IPsec tunnel:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-IPsec-VPN-settings-on-a-s...

 

Secondary IP address can be used as VIP:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Implement-a-virtual-IP-address-VIP-from-a/...

 

 

 

FortiGate
Stephan_s
New Contributor III

In my Eyes this should work

Labels
Top Kudoed Authors