FortiGate Dialup VPN between Hub and Spoke
Problem Often a company has an HQ with various external locations. The external locations sometimes have only a dynamic IP address, can arise or close very often. Depending on the situation, these are very dynamic or a company has a lot of external locations. So it is not the plan to create a separate VPN tunnel for each location. In normal operation mode only the VPN Tunnel over ISP1 should be used. If ISP1 failed the Tunnel over ISP2 should be come online. How should the VPNs be set up so that all locations can be connected to the HQ with as little effort as possible? Solution The FortiGate in the HQ can be configured in "DialUp" mode. The external locations connect directly to the HQ via a dynamic tunnel. The required reliability is achieved via one tunnel per ISP. HQ Configuration The first thing to do is to configure the two VPN tunnels in the HQ. The following settings are necessary for this: Phase 1 config vpn ipsec phase1-interface edit "Branches_ISP1"