Skip to main content
Redguy
New Member
October 14, 2016
Question

Forticlient On / Off-Net ??

  • October 14, 2016
  • 1 reply
  • 3990 views

 

We have our users setup with the Forticlient software package for web and application filtering and as an IPSEC VPN client to connect to our Fortigate gateways..

 

The gateway will assign the client an ip address out of an IP subnet which is a /24 out of the /16 range used for our company.

The Fortigates have FGT-Access enable on the insde, outside and VPN interfaces.

 

I am seeing unpredictable behaviour as to whether the clients consider themselves to be On or Off net.  Machines within the office will alternate between on and off net without any visible causes, same goes for home, regardless of the state of their vpn connection (dial-in or not). The users are not using any of our internal subnet ranges at their home networks.

 

 

Is their any way to clearly assign rules on which the client can determine if they are on or off-net ? 

    1 reply

    SteveG
    New Member
    October 17, 2016

    I find the on/off net part takes 5 minutes so sort its self out! We use EMS to manage the FortiClients and there's a field under the profile setting that lets you define what's 'on net' (onnet subnets).

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!