Skip to main content
Sinichi_Kudo
Visitor III
January 26, 2026
Question

Configuring IPsec VPN with ZTNA using FortiClient

  • January 26, 2026
  • 3 replies
  • 622 views

Can you give me step by step on how to do this?

3 replies

AEK
SuperUser
SuperUser
January 26, 2026

IPsec and ZTNA are two different remote access methods. What do you mean exactly?

AEK
Sinichi_Kudo
Visitor III
January 27, 2026

Please refer this link : https://www.youtube.com/watch?v=vjxU8I0xREU

But for the version for IPSEC not SSL

GauravPandya
Explorer
January 27, 2026

Are you looking for FortiClient VPN setting in EMS? if so may be below URL will be helpful.

https://docs.fortinet.com/document/fortigate/7.4.4/ssl-vpn-to-ipsec-vpn-migration/477942/forticlient-endpoint-configuration-migration

 

tbarua
Staff
Staff
January 27, 2026

Hi Sinchi_Kudo,

Yes, it should work as per the following document:

https://docs.fortinet.com/document/fortigate/7.2.6/administration-guide/735065/augmenting-vpn-securi...

 

Enterprise Core is the FortiGate that acts as the SSL VPN server. To configure SSL VPN, refer to SSL VPN and SSL VPN security best practices. Critical Assets are network resources that the off-net user tries to access after connecting to the VPN. SSL VPN is used in this example, but a similar configuration also applies to dialup IPsec VPN where the FortiGate acts as a dialup server.

AEK
SuperUser
SuperUser
January 27, 2026

I understand you want to configure IPsec on your FortiClient.

First you need to configure IPsec dialup tunnel on your FortiGate, then on FortiClient.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-IPsec-remote-access-with-a-full/ta-p/189452

You can also configure a Remote Access profile on EMS and push it to the client via a client policy.

Starting from FortiOS 7.6.3, you can configure the IPsec profile on EMS in a more simple way by exporting/importing xml config file.

https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-configure-a-Remote-Access-profile-on-the/ta-p/413576

Hope it helps.

AEK