Skip to main content
Ananth
New Member
April 23, 2007
Question

mail server access through vpn

  • April 23, 2007
  • 9 replies
  • 4511 views
Hi all, I read through most of the threads in VPN, but couldn' t find anything similar to our situation. We have a Fortigate 100A device, our mail and ftp servers are configured to the internal port, whenever our mail users travel abroad we frequently have problems with black listed ip' s, so we want to configure these users to connect to the mail server via vpn. Kindly advice, when we tried to connect, internet connection got lost while vpn connection was established! best regards anth.

    9 replies

    doshbass
    New Member
    April 23, 2007
    Anth, Can you give a lttle more detail on what type of VPN you are trying to use. Is it SSL, PPTP or IPSEC. When you say the internet connection is lost, is it really lost or are the remote users simply not able to browse the internet. If it is the latter then it could be that split tunneling is disabled. The split tunneling option allows users to go to non internal hosts directly from thier internet connection. You do not need to enable split tunneling and make all your vpn connected users go through your firewall, but you need to make sure you have the correct rules on the Firewall to allow this
    Ananth
    AnanthAuthor
    New Member
    April 23, 2007
    doshbass, Its PPTP VPN we are trying to configure. Is this the best way? Hope you understood our requirement, we want our traveling users to connect to our mail server through vpn. What we did so far is, we create vpn users, put them in a user group. created a new service group having http, https, pop3, smtp and ssh services created a new policy between the mail server in the ' internal' port from wan1 wan1>internal>vpn user group>mail server>always>vpn service>accept. Like when I tested this from my home system, I lost my internet connection when the vpn got connected, i can' t browse any internet sites while vpn is connected. I' ll try by enabling split tunneling. best regards anth.
    doshbass
    New Member
    April 23, 2007
    Yes this is because split tunneling is not enabled. On a windows machine, you enable split tunneling by removing the checkbox that says use default gateway on remote network. You find this under the network connections shortcut properties Networking Tab Select Internet protocol => press properties press advanced This checkbox should not be checked for split tunneling.
    Ananth
    AnanthAuthor
    New Member
    July 6, 2007
    Sorry for the delay in following up... We tried it here but couldn' t make it work. The client systems are Windows XP Home laptops. We have again started on this move to vpn again, so hopefully I can give my feedback as soon as possible.
    Contributor III
    July 10, 2007
    Hi... Why don' t you try to use SSL-VPN with split-tunnel so you don' t need configure anything on client just enable ActiveX for the firs time use and your user till can access Internet.
    Ananth
    AnanthAuthor
    New Member
    July 10, 2007
    can you explain in more detail please.....most of our clients use Windows XP Home/professional/Vista. Mail are accessed via Outlook Express/Microsoft Outlook.
    Ananth
    AnanthAuthor
    New Member
    July 11, 2007
    Is SSL VPN available with Fortigate 100A?
    Contributor III
    July 11, 2007
    You' ve just opened web browser to activate the fortissl adapter and after that just open Outlook just like we are in the office. SSL is available on any FG, for more detailed information maybe you can check the manual SSL on the CD or you can download from http://docs.forticare.com/fgt/techdocs/FortiGate_SSL_VPN_User_Guide_01-30004-0348-20070405.pdf
    rwpatterson
    New Member
    July 11, 2007
    Be careful. I don' t believe that SSL VPN is available with Vista yet. Correct me if I' m wrong. . .
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!