Skip to main content
albaker1
New Member
August 5, 2025
Question

Problems tunnel client-server IPSec through FortiClient IPSec RA VPN

  • August 5, 2025
  • 4 replies
  • 800 views

We are using a Gate running 7.4.7 as a RA IPSec VPN for our clients, and the FortiClient is version 7.4.3.1790. One of the servers has a GPO that enforces encryption between the various clients and a server, and this traffic is never placed in the tunnel. The firewall logs shows traffic to all other servers, but there is absolutely nothing to the one server for which encryption is enforced. Best way to describe this is IPSec encapsulated in IPSec. We checked the routes on the client systems, which look good. For testing, I installed and configured FC, logged into the VPN, and it connected to the server just fine. We cannot disable the encryption settings in the GPO.

 

This is a deal breaker. Does anyone have an idea of what I can try to make this work? Thank you.

4 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
August 8, 2025

Hello albaker1, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
albaker1
albaker1Author
New Member
August 8, 2025

I appreciate your time. I've continued to troubleshoot but can't get this to work.

funkylicious
SuperUser
SuperUser
August 8, 2025

can you share the details/config of the GPO in question ?

i would like to try it in a lab if i can

"jack of all trades, master of none"
albaker1
albaker1Author
New Member
August 11, 2025

Is this adequate? Thanks for your time.

 

Windows Security 1.png

Windows Security 2.png

  

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!