Skip to main content
snowman386
New Member
February 25, 2010
Question

IPSec policy server forticlient remote networks

  • February 25, 2010
  • 13 replies
  • 11554 views
Is there any way to have the forticlient automatically learn the remote networks from the policy server? i thought this was the point of the policy server that i setup. here are the details of my config: Policy based dialup vpn using xauth DHCP server assigns VIPs to the clients with no default gateway (for split tunneling) forticlient configured for automatic ipsec vpn vpn policy server has been setup with the radius user group and the phase 2 connection of the dialup vpn I want the fortigate to assign the remote networks to the forticlient based on the firewall policy that contains the vpn tunnel (or any method. this just seems the most logical). that way i can add/remove destination subnets from the address group and have the clients automatically update instead of having to touch each client. It seems that the policy server does not assign remote networks though as the only way i can communicate to the remote networks is to change dhcp to assign a default gateway or change the forticlient to a manual ipsec vpn and specify the individual remote networks. The first way is not desirable as i dont want vpn clients consuming twice as much bandwidth to browse the internet. The second is not desirable as each vpn client has to be updated when remote networks are added/removed. Hope that all makes sense. Thanks

    13 replies

    snowman386
    New Member
    March 9, 2010
    me too. the funny thing is that i put in a ticket with support and they said this feature was not available and i would have to put in a feature request! :D
    rwpatterson
    New Member
    March 9, 2010
    ORIGINAL: snowman386 me too. the funny thing is that i put in a ticket with support and they said this feature was not available and i would have to put in a feature request! :D
    That' s scary.....
    Carl_Wallmark
    New Member
    March 9, 2010
    hahaha - thats funny ! Read the CLI document, you discover a lot of beatiful functions...
    laf
    New Member
    March 15, 2010
    me too. the funny thing is that i put in a ticket with support and they said this feature was not available and i would have to put in a feature request! :D
    This is very shameful. Fortinet' s support is the worst support I ever worked with, either you pay for it, or not.