Skip to main content
wailoon_ho
New Member
October 5, 2016
Question

How to have fix ip for client

  • October 5, 2016
  • 1 reply
  • 4619 views

Hi all,

My company just bought a fortinet firewall for our HQ, all branch to connect HQ thru VPN. 

We need this VPN cause the POS system need to connect back to HQ database for synchronisation. 

 

But I have a problem, the POS is designed HQ and Client need to able to see each other. 

The Client can see the HQ database cause the IP is no change, but the HQ got problem to see the Client database cause everytime Client reconnect the VPN, the IP will changed.

 

I would like to ask, is there any way to fix the Client IP even the Client reconnect the VPN? 

Or any suggestion to solve this problem? 

    1 reply

    ede_pfau
    SuperUser
    SuperUser
    October 5, 2016

    hi,

    and welcome to the forums.

     

    How does the Client connect to the VPN - via FortiClient, or via the branch Fortigate?

    Assuming a software client:

    usually, the client receives an IP address via DHCP over IPsec. This way, there can't be duplicate IP addresses around from clients. If you want to have a fixed address for each client, you can configure a static client IP address in the FortiClient. You will then have to make sure yourself that no address is used twice (using a list or such).

     

    It would help if you specify the FortiOS version of the HQ FGT and (if applicable) the version of FortiClient in use.

    emnoc
    New Member
    October 5, 2016

    You have a  few options but if radius is used you can provide the framed-address attribute#8  to  just that client. This will ensure the client , upon authentications gets the same address ALL the time.