Skip to main content
kapil
New Member
April 26, 2018
Question

In Forticlient need to hide the publicp IP of the VPN setting

  • April 26, 2018
  • 1 reply
  • 9992 views

Hi,

   We are configured SSL VPN and IPSEC VPN. VPN users are installed by the latest Forticlient in their machines and connecting to the local network. But our clients can view the Public IP in the client configuration, So its not secure there is any possibility to hide the Public IP in clients.

 

 

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    April 26, 2018

    Please elaborate what exactly the "Public IP" you're concerning about and where they can see. NAT outside IP or FortiGate's server IP? If any savvy enough user can figure out those IP with just opening up a command prompt, and a public ip is "public" anyway. So I don't know what's your concern is.

    kapil
    kapilAuthor
    New Member
    April 27, 2018

    Whats the issue is, I have configured VPN client with my public IP for our clients, we have configured with split tunneling, then other internet traffic of the user will be forwarded to their network.So our public ip will not be  advertise.

    We need to give some previlege at the user end, because there is possibilities to share our public IP and user name / passwd with other and there is risk.

     

     

    Toshi_Esumi
    SuperUser
    SuperUser
    April 27, 2018

    I still don't quite get what you're trying to say. "Your public IP" is a part of public IP subnet your organization has been allocated by ARIN? And you provide internet service to your customers with "your public IP" at those VPN client locations?

    Or you're using those public IPs to each VPN client tunnel IP, which you don't have to? "Your public IP" can be reached only through your network because that's where the prefix is advertised toward other Internet companies (peers) via BGP. They can't be routed to a third-party ISP's circuit wherever the VPN user is located.

    Instead, if you're talking about the server (FortiGate) IP to connect VPN to, yes, of couse if a user bleaches server IP/URL w/ username/password, the person who got the info can get connected. No way to prevent it unless deploying two factor auth to add another layer.