Skip to main content
dbelflower
New Member
September 8, 2022
Solved

IPsec Split Tunnel with exception

  • September 8, 2022
  • 1 reply
  • 4862 views

We use a website that authenticates user access based on our office public IP address.  I have a vpn user that needs access to this website.  How can I force access to this site for vpn users to reflect our public IP rather than their home IP?  We would like to keep using split tunnel for all other internet access.

Best answer by gfleming

OK.... so have you checked other stuff? Do you have a policy allowing that traffic? Have you verified that traffic is in fact going across the tunnel? Have you done debug flow? Traceroute? Anything to help us help you further?

1 reply

sagha
Staff
Staff
September 9, 2022

Hi dbelflower, 

 

For this specific website, you can add its public IP to the list of addresses in split tunneling. 

This way traffic would be routed to FGT via vpn tunnel and then you can allow the access towards internet for this traffic. Flow would look something like this: 

 

Client  -> VPN tunnel -> FGT --> internet -> website

This way traffic from client would use public IP of FGT. 


Hope this helps. 

 

Regards,

Shahan Agha

dbelflower
New Member
September 9, 2022

Unfortunately I can't access the website using its public IP from our office.  It redirects to another page.

gfleming
Staff
Staff
September 9, 2022

You would still add the public IP to the split tunnel list. When the remote user tries to access the page using domain name it will resolve to public IP and route over the VPN to your FGT and out your office public IP as source. However, the server will see that the client is using domain name and will present the correct web page.

 

https://www.educba.com/virtual-host/