FortiClient with FortiNet provided DHCP
- April 1, 2020
- 1 reply
- 10114 views
Hi,
Currently I have my FortiClient VPN set up with IP addresses from a range. This causes some issues with one specific application as everytime when the clients set up a VPN session they get the first available tunnel and IP address. The application doesn't like that as it remembers the client and IP address, so I am looking into the option to use DHCP provided IP addresses (preferably from the Fortigate)
I created a new VPN tunnel with a different PeerID, and on the tunnel interface set up DHCP over IPsec and gave the Tunnel interface an IP address in the same subnet as the DHCP range (See attached: Interface IP 10.10.255.1 and DHCP range 10.10.255.2-254).
FW policy have been created to allow traffic.
It looks like the VPN is completed and I seem to get an IP address from the DHCP range, but the tunnel stays up only seconds and I can't get to anything on the Internal network.
I assume something is wrong with the Tunnel interface configuration, so hopefully someone can point me in the right direction to get this working.
Also does anyone has this working and can they confirm that the clients keep the same IP address during the lease period even after they log off and log on again? Or should I make DHCP reservations for the clients that need to keep the same IP address for longer than a day?
I know it's a lot of questions and hopefully I can resolve it.
Many thanks again,
Jan
