Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ashik_Sheik
Contributor II

IPSec VPN 5.4.1 , site-to-site, dial-up User option is not working

Hi 

 

I am trying to setup Dailup user for site to site because in HUB i have Static IP and Branch have no IP .So can anyone help me to setup dailup for site to site to avoid going for Static and Dyndns for spoke .

 

Regds

 

Ashik

Ashu 

 

Ashu
3 REPLIES 3
brycemd
Contributor II

I think what you are looking for is using Aggressive mode in the site to site rather than Main mode. This way you can do a proper ipsec site to site.

 

It allows you to configure the tunnel when one or both have dynamic IPs.(Page 48 in the document linked above)

MikePruett
Valued Contributor

I have configured this type of deployment in every version of FortiOS including 5.4.x without issue. Works like a champ

Mike Pruett Fortinet GURU | Fortinet Training Videos
Ashik_Sheik

Oh Great can you help me to configured .

 

My Queries

 

1. Head Office:when i choose dailup user, Preshared Key option is disabled .

2.Head Office :What to select Aggressive  or Main ID options

3.Branch - Static IP with Preshared Key is must to not 

4.Branch - Peer option Aggressive or Main ID 

 

Thanks 

 

Ashik

 

Ashu 

 

Ashu
Labels
Top Kudoed Authors