Skip to main content
CraigCCNZ
New Member
June 25, 2024
Solved

How do I avoid using default gateway on the remote network in FortiClient VPN

  • June 25, 2024
  • 5 replies
  • 7091 views

We are currently in the process of switching over to the FortiClient VPN (v7.0.0.0029) from the DrayTek Smart VPN Client and I notice that all of my traffic is now being piped through the VPN, instead of just the traffic that requires it.

 

Our FortiClient is set up to use IPsec VPN.

 

The DrayTek VPN has a setting named Use default gateway on remote network and I always have this switched off.  I'm trying to find a similar setting in the FortiClient VPN.

 

Sorry.  I'm not overly familiar with all the network jargon, so please forgive me for that.  I see a bunch of settings under Advance Settings, but nothing that appears equivalent to the DrayTek setting.

 

Thank you in advance for any assistance provided.

Best answer by CraigCCNZ

This was fixed in the backend by our system admin.  No change to the client was required.

5 replies

srajeswaran
Staff
Staff
June 26, 2024
CraigCCNZ
CraigCCNZAuthor
New Member
June 27, 2024

Thank you for the info.  It sounds like it's not just a straightforward client setting.  Something needs to happen on the VPN host.  I've forwarded these links on to our system administrator.

hjezzapaula
Staff
Staff
June 26, 2024

Hi,

You may configure split-tunneling so remote clients access to internet will be forwarded to their local gateway.

config vpn ipsec phase1-interface
edit "<Dialup VPN Name>"
set ipv4-split-include "<Internal Network Address Name>"
end

Remote client will only use the tunnel for "Internal Network Address" destined traffic.
See: https://community.fortinet.com/t5/FortiGate/Technical-Note-FortiClient-Dialup-IPsec-VPN-Split-Tunneling/ta-p/192207

CraigCCNZ
CraigCCNZAuthor
New Member
June 27, 2024

Thank you for the info.  It sounds like it's not just a straightforward client setting.  Something needs to happen on the VPN host.  I've forwarded this link on to our system administrator.

CraigCCNZ
CraigCCNZAuthorAnswer
New Member
July 3, 2024

This was fixed in the backend by our system admin.  No change to the client was required.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.