New Member
January 25, 2016
Question
IPsec VPNs ALWAYS route hop through DMZ interface IP Address ?
- January 25, 2016
- 1 reply
- 8152 views
Firewall : 60D with wifi
firmware : V5.2.3 Build670 (GA)
Operation mode : NAT
IPSEC VPN dhcp IP client Range: 192.168.60.10 - 192.168.60.20
VPN Client only can access the IP 192.168.10.70 (NAS)
symptom
When VPN Client trying to trace route 192.168.10.70
The first hop is ALWAYS the IP address of the FortiGate' s DMZ interface, even though I have the FortiGate' s DMZ interface administratively down.
When i change the DMZ IP and trace route again, the first hop IP will be change accordingly.
When I change the DMZ IP to 0.0.0.0/0.0.0.0 and trace route again, the first hop IP will be change WAN-1 Interface IP (Internet IP)
why the first hop IP not the gateway ip ? how can i fix this problem
thanks
Ringo
