Usg110 to usg60 ipsec Tunnel

jannisb Posts: 11
First Anniversary First Comment
edited April 2021 in Security

Hello i m try in to setup an ipsec Tunnel. From A Usg110 with A static Adress to A usg60 which is behind a nat Router with A dynamic Adress.

Is this even possible? Can i use dyndns on the side of the dynamic Adress for the NAT Router or the usg60?

If this would Work i could build A site to. Site Tunnel.

If not can i build A site with dynamic peer Tunnel?


  • Ian31
    Ian31 Posts: 168  Master Member
    First Anniversary 10 Comments Friend Collector First Answer

    If USG60W is behind NAT,

    Here the recommend solution,

    1. On the NAT router need to configure port forwarding UDP500,UDP4500 mapping to WAN IP of USG. On USG110, you can use site-to-site with static IP or DDNS for USG60W.
    2. If you cannot configure the NAT router. Then, on USG110 using site-to-site with dynamic peer for USG60W.

    Note: Please configure the IPSec Phase 1 local id on USG60W to type DNS and give a

    unique string as id. So that USG110 can easy identify the peer.

Security Highlight