Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ispcolohost
Contributor

Any way to have dial-up AND site-to-site VPN between same two locations?

Hey all, I've got a location with fortigate/ipsec site to site VPN; i.e. branch to HQ.  There is a user on wifi at branch, where wifi only has internet access.  Internet access from wifi leaves the local fortigate via the same interface the site to site vpn traffic uses, and that user would like to VPN to HQ.

 

Is there some combination of IPSec settings that will allow the site to site VPN and "dialup" users to connect to the same target Fortigate from the same source WAN IP?  I've attempted aggressive mode IKEv1 with a variety of combinations of peertype any vs one, unspecified, and then either phase 1 local id set or not set, etc. but have not arrived at a combo that allows both to exist in harmony.

1 REPLY 1
sw2090
Honored Contributor

you need to limit the dial up tunnel to a specific peer-id. Otherwise the FGT cannot determine the correct tunnel and gets messed up ;)

Works fine here this way.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors