Skip to main content
dosforever
New Member
February 7, 2018
Question

How to access VPN client host from inside firerwall

  • February 7, 2018
  • 1 reply
  • 4003 views

first all, I'm not good at English, I don't know if I expressed exactly.

Firewall:Fortigate-200A, Firmware Version:3.00

The remote user can access to the HQ LAN inside firewall by PPTP dial up or Forticlient IPSec client. The remote host has the IP address segment same with the LAN host inside the firewall.

but I have a question. when VPN tunnel is built, how can I initiate access to the remote host?

I can not ping through the remote host, can not access remote host by Windows remote desktop, etc. Just like the remote host are not in the LAN.

1 reply

ede_pfau
SuperUser
SuperUser
February 10, 2018

hi,

 

and welcome to the forums.

 

Well, it is not in the LAN. So the FGT has to do routing to direct traffic to the client.

 

This is a technical peculiarity of dial-in VPNs. If you establish a client tunnel and look at the Routing Monitor you will see that the FGT has inserted a route between the FGT and the client automatically. But, both addresses are restricted to this one address by the '/32' netmask. So, traffic directly from the FGT can reach the client, and vice versa, but a host on the LAN cannot.

You cannot 'override' this automatic route as it already has the highest priority and lowest distance.

 

The same question pops up here in the forums regularily, and the answer is always the same: a client connection is not a site-to-site connection.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!