Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Rahuls
New Contributor

Using secondary IP for VPN termination

Hi,

We have two different 600C firewall clusters at 2 locations with different internet links.

Now, my query is can I have same secondary IP on both the firewall's WAN interface while primary IPs being unique on individual units.

 

Can anyone advise on this whether thisis going to work?

 

Regards,

Rahul

2 REPLIES 2
EMES
Contributor

The firewalls will allow you to do it but because they secondary aren't unique traffic will not route properly.
ede_pfau
Esteemed Contributor III

Strange question. Why would you want this?

And I agree, if you terminate the VPN on the identical secondary IP, how would the FGT know which of the 2 identical addresses you mean - the local or the remote one?


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors