Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlbertoMantovani
New Contributor

SSLVPN on VRRP ip shared

hi all !

i've a question :

i've 2 FGT 200F cluster on different location connectet by several link that share the my own BGP pubblic IP access in VRRP.

so every cluster have different phisical IP on WAN interface and a COMON VRRP Address that i use to terminate IPSEC VPN declaring the Local Gateway ip address.

In case of Failiure of the Primary location the Ipsec VPN tunnel will be closed on the same VRRP address on other location.

Is it possible to use same configuration for SSLVPN?

In gui i have not found the possibility to specify the IP where the sslvpn listen to,

but only The INTERFACE where the services in Listen on - there are some other workarround?


I'm in 7.0.12 Nat mode

Thanks Alberto

1 Solution
msanjaypadma
Staff
Staff

Hi @AlbertoMantovani  ,


In both scenario, its completely depends upon the upstream how forwarding happen towards firewall.
Basically I can say, you can try with it.
However  as per lab behavior , for VRRP IP its not listening to SSLVPN interface. 

Thanks,

Mayur Padma

View solution in original post

5 REPLIES 5
Anthony_E
Community Manager
Community Manager

Ciao Alberto,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
msanjaypadma
Staff
Staff

Hi @AlbertoMantovani ,

 


As I have understand you are trying to add VRRP virtual  interface ip address into SSLVPN listening interface, If I am wrong please correct me.

I have tested this in my LAB setup, however it didn't work,  traffic for sslvpn port was getting drop in fortigate. However vrrp virtual ip address is responding to fortigate https traffic. 

I believe there is certain limitation where firewall SSLVPN interface is not listening to vrrp ip address. 

 

You can consider different approach to achieve this either by creating loopback interface.

https://community.fortinet.com/t5/FortiGate/Techical-Tip-Access-SSL-VPN-from-Secondary-IP-only/ta-p/...

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-secondary-IP-address-for-...

Thanks,

Mayur Padma
AmandaJansen

Thanks, my issue has been fixed.

AlbertoMantovani
New Contributor

First of all - Thanks for your time! i enjoyed it


I will study the possibility of using the loopback interface for ssl-vpn
My goal is to use the same IP address
in shared VRRP for 2 FWs (located in different datacenters)
I suppose the VIP solution doesn't work, because if I try to configure
the same VIP on 2 different Firewalls connected with L2 links
I think I could crash in an IP Conflict
What do you think about it?

Thanks

msanjaypadma
Staff
Staff

Hi @AlbertoMantovani  ,


In both scenario, its completely depends upon the upstream how forwarding happen towards firewall.
Basically I can say, you can try with it.
However  as per lab behavior , for VRRP IP its not listening to SSLVPN interface. 

Thanks,

Mayur Padma
Labels
Top Kudoed Authors