FortiGate as dialup VPN client - reverse path checking problem
- September 9, 2016
- 3 replies
- 9502 views
Hello all,
I need configure FortiGate as VPN dialup client. I try to setup it in my lab - please see image "FGT_dial_client.jpg".
My goal is to connect firewall "FGT VPN REMOTE" to "FGT VPN SERVER" as dialup client, so PC 192.168.1.10 can reach to network 192.168.20.0/24. I made setting according to "FortiOS Handbook - IPSec VPN", chapter "FortiGate dialup-client configurations". I am able to bring up VPN tunnel, data from 192.168.1.1 reach FGT VPN SERVER, but on FGT VPN SERVER I get error message "reverse path failed".
I investigate route table on FGT VPN SERVER and find that there is no route back to 192.168.1.0. I tried to make static route through VPN tunnel interface, but I cannot - I cannot choose VPN tunnel interface as device when I create static route, VPN tunnel interface is not visible in drop down menu in GUI. I tried it via CLI, but no success.
Please can you help me with how I can set route back to 192.168.1.0 on FGT VPN SERVER? Or is something wrong in my config? Thank you in advance for any help.
Best regards
Lukas Mecir
P.S. - Site-to-site VPN is unfortunately not an option, because in real FGT VPN REMOTE device will be moved between many locations and will get WAN IP address dynamicly.
