I’m trying to setup an IPSEC tunnel between a VyOS (static IP) and a Fortigate (dynamic IP).
I’ve managed to get a tunnel running using named based peer (@FGT00) but I cannot bind a name based peer to a VTI interface:
[quote]admin@lynx# commit
[ vpn ]
Error: an IP address is expected rather than “@FGT00”
Cannot find device “vti0”
Cannot find device “vti0”
[[vpn]] failed
Commit failed[/quote]
Not sure why, I guess it’s either by design or a bug/missconfig, I’m convinced it’s the former but would like someone to confirm if that is the case.
Any other ideas on how to have an interface mode VPN with a dynamic IP remote peer? I’ve also tried NHRP (had this working agasint a cisco router before) but the fortigate doesn’t seem to support NHRP (even though it supports GRE over IPSEC)
Thanks all