Skip to main content
exidinus
New Member
September 16, 2020
Question

VPN IPsec Dialup - FortiClient

  • September 16, 2020
  • 1 reply
  • 2106 views

Hello.

Sorry, I didn't know which section is better to write VPN or Firewall

 

Users must remotely connect to the central office and work with authorized services. Users can be included in groups for which the service should be available. IPSec pre-shared key There are 2 rules in the firewall

 

show
config firewall policy
    edit 4
        set name "vpn_ipsec_1"
        set uuid **********************
        set srcintf "ipsec_1"
        set dstintf "lan"
        set srcaddr "ipsec_1_range"
        set dstaddr "server_1"
        set action accept
        set schedule "always"
        set service "ALL"
        set inspection-mode proxy
        set comments "VPN: ipsec_1
        set nat enable
    next
end

 

 

config firewall policy
    edit 5
        set name "vpn_ipsec_2"
        set uuid ***********************
        set srcintf "ipsec_2"
        set dstintf "lan"
        set srcaddr "ipsec_2_range"
        set dstaddr "server_2"
        set action accept
        set schedule "always"
        set service "ALL"
        set inspection-mode proxy
        set comments "VPN: ipsec_2
        set nat enable
    next
end

 

The crux of the pain is VPN_2 is not connected on the client, but if you disable rule number 1, then VPN_2 is connected on the client. Tell me where to dig?

1 reply

Mrinmoy
Staff
Staff
August 30, 2023

Please share the vpn config and user group config here

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!