Skip to main content
rezafathi
Explorer III
April 2, 2024
Solved

Native l2tp ipsec remote access vpn

  • April 2, 2024
  • 2 replies
  • 1362 views

Hi

We have some remote users with windows 7 and forticlient vpn app does not install on windows 7. I created a native l2tp vpn tunnel, it created 2 firewall policies automatically. I also want to have split tunneling enabled. When they connect via this tunnel, they can not connect to our internal network nor internet. What should i do to have access to internal networks and internet at the same time? Thanks.

Best answer by ozkanaltas

Hello @rezafathi ,

 

You can review this document. This way should work.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Split-tunneling-on-L2TP-IPSEC-VPN-between/ta-p/195645

2 replies

ozkanaltas
Valued Contributor III
April 2, 2024

Hello @rezafathi ,

 

You can review this document. This way should work.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Split-tunneling-on-L2TP-IPSEC-VPN-between/ta-p/195645

hbac
Staff
Staff
April 2, 2024

Hi @rezafathi

 

When connected to the VPN, you need to check your routing-table 'route print'. Also make sure you have firewall policy to allow the traffic to internal network. If you have proper routes, you can run debug flow on FortiGate to see if traffic is being dropped. https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connectivity/ta-p/192560

 

Regards, 

rezafathi
rezafathiAuthor
Explorer III
April 2, 2024

Thanks. On windows i can not select mschapv2. Only pap works. Why?