Skip to main content
iron151
New Member
December 5, 2018
Solved

Cant Access Local Lan when using IPSEC VPN

  • December 5, 2018
  • 4 replies
  • 15272 views

Configured IPSEc vpn on fortiagte 100(v6.0.3 build0200). When user connects using forticlient, i am able to access the lan resources behing fortigate but i am unable to use local LAN and also want local internet traffic should not go through the tunnel.

    Best answer by ede_pfau

    @lobstercreed: helpful, but OP is using IPsec VPN.

     

    and the same applies to IPsec VPN: in the FortiClient, you can enable "split tunneling" and specify the subnet(s) behind the FGT which should be routed over the tunnel. All other traffic will then use the local gateway - local resources like printer, and the internet via the local router/modem.

    4 replies

    lobstercreed
    New Member
    December 5, 2018

    Hi Deepak,

     

    In the VPN -> SSL-VPN Portals settings, there should be a slider to enable split-tunneling.  It sounds to me like that is not enabled on the portal that the user is mapping to (you can check the mapping under VPN -> SSL-VPN Settings).

     

    - Daniel

    ede_pfau
    SuperUser
    ede_pfauAnswer
    SuperUser
    December 6, 2018

    @lobstercreed: helpful, but OP is using IPsec VPN.

     

    and the same applies to IPsec VPN: in the FortiClient, you can enable "split tunneling" and specify the subnet(s) behind the FGT which should be routed over the tunnel. All other traffic will then use the local gateway - local resources like printer, and the internet via the local router/modem.

    lobstercreed
    New Member
    December 6, 2018

    Thanks Ede, I totally missed that detail.  

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.