Skip to main content
BigMike
Explorer
November 16, 2023
Question

Internet down after using Forticlient VPN

  • November 16, 2023
  • 13 replies
  • 9891 views

    I am using win10 and using FortiClient VPN Only version. When I connect the vpn, my internet down and no one can use remote desktop to connect my PC either.

   There is a post discussed it: https://community.fortinet.com/t5/Support-Forum/Lost-internet-connection-when-using-forticlient/td-p/211201 

   I checked the route table and there is one new route for 0.0.0.0, so there are two 0.0.0.0 routes.

   But when I try to use 'route delete 0.0.0.0' command according to the post , it only delete the system default one, and cannot delete the one which VPN client add.

  So I googled this post:windows - Can't change routes with VPN Client - Super User.

  It has the same issue and he found the reason is " I examined the issue with Rohitab and found out FortiSSL Client watches the routes table with the NotifyRouteChange IP Helper API call."

  His conclusion is Forticlient vpn will monitor the route table and fix it automatically.

 

  I am not network expert, just an normal user, I dont know to do with it. I even cannot judge if the problem is caused by the route table.

 

  Can anyone give some hints?

 

  Thanks

FortiClient 

  

   Can you give some hints?

13 replies

AEK
SuperUser
SuperUser
November 16, 2023

Most probably caused by the default route injected by VPN.

This behavior can be disabled at your client side (with most VPN clients) or at VPN server side.

E.g.: On your FortiGate, you can enable Split Tunneling on your SSL-VPN portal not to inject default route.

AEK
sw2090
SuperUser
SuperUser
November 16, 2023

not sure if you can prevent FortiClient from doing that. Anyways it would not make sense because in this case it would render your vpn useless because it will not be hit by any traffic without a route.

I'd recommend to change the other end of that VPN Tunnel to do split tunneling so it wouldn't inject any new default route but routes to the specified subnet(s).

smayank
Staff
Staff
November 16, 2023

Hello 

When you connect to SSL VPN firewall push routes towards the client .

In your case firewall might be pushing default right from ssl vpn tunnel
you can check internally and configure split tunnel.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enabling-split-tunnel-feature-for-SSL-VPN/ta-p/198108
Thanks & Regards
Mayank Sharma

BigMike
BigMikeAuthor
Explorer
November 16, 2023

I also notice when I connect the VPN, the other cannot use Remote Desktop(RDP) to connect my PC, is it also split-tunnel issue?

AEK
SuperUser
SuperUser
November 16, 2023
  • "No" if the client is on the same network as the server
  • "Yes" if the client is on another network, because response from server will be sent through the wrong default gateway (VPN GW)
AEK
BigMike
BigMikeAuthor
Explorer
November 16, 2023

Hi,

I am using the VPN-only version of Forticlient, how to enable the split-tunnel feature?

 

Snipaste_2023-11-16_23-05-32.jpg

sw2090
SuperUser
SuperUser
November 16, 2023

Split tunneling cannot be enabled in FortiClient bacause it is a feature of FortiOS. It has to be enabled on the FortiGate your are connecting to.

AEK
SuperUser
SuperUser
November 16, 2023

In case you don't have access to the remote FortiGate then you have to delete manually the injected default GW once you establish the SSL VPN connection.

AEK
sw2090
SuperUser
SuperUser
November 17, 2023

As said: removing the injected default route will make your internet accessible again but it will also render your vpn useless as no more traffic will hit it...

burtos
New Member
November 29, 2023

could try and remove the ipv6 option (so it doesnt try and get a ipv6 address) on both the laptop networks connection and vpn connection. Noticed on a few users that internet drops, when users have both ipv4 and ipv6 option selected. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!