Hi Team,
Recently, Fortinet has removed or changed multiple features, and some of the previously available configurations are no longer supported. This impacts our technical setup and limits our ability to achieve the required VPN configuration.
Earlier, we had the following working configuration for Remote Access IPsec VPN:
Authentication via LDAP
IP assignment through Internal DHCP Server (DHCP over IPsec)
IKEv1 – Aggressive Mode
Full Tunnel mode
Using FortiClient 7.4.1
This setup was functioning successfully without major issues, except that Split Tunnel could not be enabled due to conflicts affecting the internal DHCP server.
Now we want to understand how we can achieve all requirements in a single IPsec configuration, with the latest Fortinet restrictions:
Use IKEv2 instead of IKEv1
Obtain VPN client IP from our internal DHCP server
Continue using LDAP credentials for VPN authentication
Support both Full Tunnel and Split Tunnel modes
Please advise how we can achieve all of the above in a single IPsec setup, or if any architectural changes are required under the new Fortinet limitations.
Thank you.
hi,
have a read at
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
| User | Count |
|---|---|
| 8 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.