This section contains information about IPsec VPNs and SSL VPNs. All recipes and videos were made using FortiOS 5.4.

All VPN recipes



Expert VPN


Leave a comment:

Before commenting, please read the site's comment policy. Only questions related to documentation will be answered. For other concerns, please contact Fortinet support.

  • AF


    I’m new to the VPN configuration. Need the advise from the expert.

    My FGT connected thru ADSL Modem (Not Bridged) and now i’m trying to configure the VPN Access. Can it be done in this kind of installation? I’m trying but it seem it cannot go thru (No Connection). Hope can advise.


    • Keith Leroux

      Hi AF,

      You should try to put your modem in bridge mode so that the FortiGate can get an external IP.

      • AF

        I try to but the things is i have 2 internet line. When i connected via bridged both to the FGT there is no internet connection. How can i solve this issue.

        • Keith Leroux

          Hello AF,

          I’m not entirely sure, so I recommend that you contact support at support.fortinet.com. Best of luck~

  • Dee


    Is there a limitation of VPN in terms of number of users connected to fortigate

  • StefanoF

    Hello all,

    I just created site to site tunnel to trainning but now i can’ t delete it.

    i just delete phase 2 static route and policy the reference of the vpn site2site is zero but i can’t delete the phase 1

    i have an fortigate 80C

    IDEA ?? help me

    • Hi Stefano, To delete the site-to-site VPN you need to delete everything associated with it. You also won’t be able to delete any part that is still being referenced by another part of the VPN. Usually I delete in the following order: security policies, firewall address groups, firewall addresses, static routes, and then the tunnel itself.

    • Jochen O

      Hi StefanoF,

      If the reference in the GUI is 0 this means it is most likely a CLI only object that is using the VPN interface.

      This might very well be OSPF for example. If a tunnel interface is located in the OSPF passive-interfaces it is still referenced, but because this is not shown in the GUI it will show 0.

      The fastest methods is backing up the configuration and find through the config file to see where it is referenced.

      In the CLI I would do the same using the ‘grep’ command.

  • Florian

    Hello all,

    I would like to create à PPTP VPN on a Fortigate 5.4 GA. Is it possible ? How I can do it ?

    Thanks in advance !

  • mir

    HI ,
    An a Newbie.
    can any one help me on how to setup two FortiGates on VM to implement Site-to-Site VPN.

  • Kevin Blanchette

    I am currently trying to set up a VPN on a DMZ, but except of having any any policy, i can get thru by opening the ports for either PPTP and L2TP.

    Is there any documentation that I can get on how to configure the fortigate to be able to connect to the vpn?


    • Keith Leroux

      Hi Kevin, sorry, I’m not aware of any documentation for L2TP/PPTP VPN on a DMZ, but if I can get the information I’ll try to build a recipe. You should contact Fortinet Support to see if they can assist you directly.

  • Eddie

    I have seen a bunch of simple posts with quick answers online about setting up IPSEC VPN between two fortigates as a backup to MPLS. None of these posts give much detailed information about how to correctly accomplish this, and some reference using OSPF with BFD, while others try to get away with DGD. In an MPLS environment, we’re all going to want to see if a single peer goes down, only that peer fails over, not all peers failing over to VPN in the event of a single branch MPLS issue. I’m planning on putting my MPLS router on WAN2 while leaving Internet and IPSEC tunnels on WAN1 and need some sort of dynamic failover/back and am unsure what to use. Can someone make a recipie that encompasses all that is required to make this setup a reality? Is there anything needed to be supported by the MPLS ISP (AT&T) to make this work? …and can we also assume IPSEC VPN tunnels should be setup in a dynamic HUB and SPOKE method as well to keep everything as functional as possible?