Skip to main content
jgillies01
Staff
Staff
November 4, 2019

Technical Tip: Multiple concurrent L2TP/IPsec access

  • November 4, 2019
  • 0 replies
  • 10359 views

Description
This article describes how to access L2TP/IPsec VPN tunnel from different Windows native clients behind the same NAT IP address.

Useful link:
Fortinet Documentation: New route-basedIPsec logic


Scope
FortiGate v5.6.3
FortiGate v6.0
FortiGate v6.2

Solution
Formerly FortiOS was creating only one Dialup interface for every L2TP/IPsec tunnel, so If two users are behind the same NAT device, only one of them could successfully access the tunnel.

As of FortiOS version 6.0 & 5.6.3, a new behavior is implemented for routing traffic to IPsec dialup tunnels.
A new option is added to IPsec phase1 configuration using this command:

# config vpn ipsec phase1-interface
edit “VPN-phase1”
set net-device enable
end 

net-device enable” creates dynamic interface for each dialer.
This helps FortiOS distinguish multiple requests coming from multiple Windows clients NATed by the same IP address.


 
 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!