Skip to main content
Adeel12
New Member
March 11, 2025
Question

Forticlient ZTNA Adding default route on split remote tunnel

  • March 11, 2025
  • 4 replies
  • 1880 views

Hi All,

 

I am facing an issue with my IPsec remote VPN split tunnel configuration on FortiGate. When a user connects using FortiClient-VPNonly addition client software, it works fine. However, when the user connects using the FortiClient-ZTNA edition, the default route (0.0.0.0/0) is added to the host machine, forcing all traffic through the VPN, even though split tunneling is configured.

Anyone has any idea?

 

4 replies

AEK
SuperUser
SuperUser
March 11, 2025

Hi Adeel

Which FortiClient version?

AEK
Adeel12
Adeel12Author
New Member
March 11, 2025

Its Updated Version v7.4.2.1737

AEK
SuperUser
SuperUser
March 11, 2025

Didn't find such issue in the known issues list.

I already configured split tunnel IPsec for FCT 7.4.0 (licensed edition) and it worked fine.

If you can't try FCT 7.4.0 or 7.4.1 (just to make sure) then I suggest to manually remove the injected gateway while you initiate a ticket with TAC for a sustainable solution.

AEK
Adeel12
Adeel12Author
New Member
March 11, 2025

Fortigate Firewall Version is V7.2.8 Build 1639, and Forticlient-ZTNA edition version is v7.4.2.1737. 
Thanks for your kind response. The issue is fixed for me by reinstalling the Forticlient. IDK what's the issue, but it fixed automatically.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!