Skip to main content
InventX
New Member
February 15, 2017
Question

Win. Native Rem. Acc. throug L2TP-IPSec VPN from Windows 10 to FGT60E behind DSL router

  • February 15, 2017
  • 31 replies
  • 60056 views

I use the Fortigate60E as firewall and router behind a DSL modem. The FGT is connected to the DMZ port of the DSL modem (FritzBox 7360). I'm able to log in to the FritzBox on port 442, and the management port of the FGT is HTTPS: 444. I'm also able to login to the FGT from a remote desktop. The Physical settup is: Internet (public IP) <--> Frtizbox (192.168.1.1) <-->  (192.168.1.20) Fortigate 60E <--> (192.168.2.1/24) Lan Clients. The Lan Clients is on port 2 (as Interface, not as LAN port).

port 2 (internal1) has static IP adress 192.168.2.1 with DHCP Server (s.i.p: 192.168.2.10, e.i.p: 192.168.2.254) no Secondary IP Address. The wan1 interface has addressing mode: DHCP (from FritzBox, which assigns static IP address: 192.168.1.20) with Acquired DNS 192.168.1.1 and Default Gateway: 192.168.1.1 (= FritzBox LAN port 1). Retrieve default gateway from server is on and Override internal DNS is also on.

 

I'm also able to port forward VOIP settings to a local PBX server and WebDav ports to a NAS in the local network. When I create a IPSec tunnel with the IPSec Wizard and choose for Remote Access and Windows Native, and fill in all settings:

 

2) Incoming Interface: Wan1 (192.168.1.20), Pre-shared key, User Group (VPN-Users)

3) Local interface: Lan-Clients (192.168.2.1/24), Local Address: all, Client Address Range: 10.10.100.1-10.10.100.100, Subnet Mask: 255.255.255.255

 

 

When I try to connect from remote Client I see the tunnel is coming up, but the VPN Events only are showing negotiate failures on the IPSec phase 1 connector.

What should I do to make this work?? I've spend days searching the Forti Cookbook and forums and Youtube video's, but it won't work..

Please help!

31 replies

ede_pfau
SuperUser
SuperUser
February 16, 2017

There are a few things that I don't understand:

 

1- you state that the FB is used as a modem but on the other hand it hands down a private IP address to the FGT - so it's routing, right?

I'm familiar with a modem setup in front of the FGT where the modem is in 'brigde' or 'pass-through' mode and the PPPoE handling of the ADSL WAN line is completely done on the FGT. Here, the wan port receives the public IP address which makes many things less complicated. I'm not sure a FB can be put into that mode - you could  designate a LAN port of it as "exposed host". The transfer network between FB and FGT doesn't need to be dynamic at all, a static setup would be appropriate (but this is not the reason for the tunnel failure).

 

2- the VPN needs to handle NAT traversal. I've got no clue whether a L2TP tunnel can do that, NAT-T is a IPsec feature.

 

3- you need a static route on the FGT for the client LAN address space, i.e. 10.10.100.0/24, pointing to the tunnel interface. Otherwise, traffic with these source addresses will be dropped by the FGT as 'unknown'.

BTW, the mask you posted is a /32 and good for nothing. Probably a typo.

InventX
InventXAuthor
New Member
February 16, 2017

Hello Ede,

 

Thank you for your reply.

1 - Indeed the FB is a DSL modem connected with the DSL port to internet. The FGT is with its WAN1 port connected to LAN port 1 of the FB. The FGT is getting a internal IP, so indeed the FB is routing. But I also markt port1 of the FB as Exposed port, so thats why I can connect to the FGT from the public IP of the FB. Unfortunately I can't setup the FB in bridge or pass-through mode. This model doesn't support that. And beside that, the customer don't have the username/password for the DSL connection to setup the PPPoE settings in the FGT.

 

2 - The tunnel I'm trying to create is a L2TP-IPSec tunnel, so I think this should be possible?

 

3 - I've tried to create the tunnel on several ways, thru the Wizard, as cusom VPN tunnel, with CLI. The only time the tunnel is getting up is when I created the tunnel with the wizard. The wizard also creates the Address (Eqraft_Goes_Range) as a IP Range (10.10.100.1-10.10.100.100) and creates two IPv4 Rules from VPN tunnel to Wan1 (NAT disabled, source and destination "All", Service: "L2TP") and from VPN tunnel to Lan Clients (NAT enabled, source: "Eqraft_Goes_Range", destination: "All", Service: "All") 

 

Should I also create a static route? and how should that look like?

 

Thank you for helping me.

InventX
InventXAuthor
New Member
February 17, 2017

Hi All,

 

I've created a ticket with the support department, after some testing they tell me it isn't possible to create and use a L2TP-IPsec VPN tunnel, because this FGT is on the LAN site of a DSL modem/router....:

 

Thank you for the nice update. As I research about your issue and figure it out Since your FGT is behind an internet modem(with a private IP) this L2TP/IPsec(Microsoft VPN) config is not supported. L2TP/IPSec on Windows only supports transport-mode(does not work well with port forwarding and NAT). Because of this, the FGT requires a routable public IP address on it's WAN interface.

 

Can annybody tell me if it is possible or not? 

 

If it isn't possible, how can I give remote workers the best way to connect to the private network? I've tried a SSL-VPN with the Forticlient, but then I get a symetric bandwith and the DSL line is 111Mbps download and 33 Mbps upload.... The SSL-VPN only could copy files from remote to local (and also from local to remote side) with +/- 28 Mbps..

 

Hoping somebody can help..

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.