FortiCare Service Development Discussions
Ask questions and join FortiCare Services
ankitkamboj
New Contributor

Request for Solution: IKEv2 IPsec VPN with DHCP, LDAP, Split Tunnel

 

Hi Team,

Recently, Fortinet has removed or changed multiple features, and some of the previously available configurations are no longer supported. This impacts our technical setup and limits our ability to achieve the required VPN configuration.

Earlier, we had the following working configuration for Remote Access IPsec VPN:

  • Authentication via LDAP

  • IP assignment through Internal DHCP Server (DHCP over IPsec)

  • IKEv1 – Aggressive Mode

  • Full Tunnel mode

  • Using FortiClient 7.4.1
    This setup was functioning successfully without major issues, except that Split Tunnel could not be enabled due to conflicts affecting the internal DHCP server.

Now we want to understand how we can achieve all requirements in a single IPsec configuration, with the latest Fortinet restrictions:

New Requirements

  1. Use IKEv2 instead of IKEv1

  2. Obtain VPN client IP from our internal DHCP server

  3. Continue using LDAP credentials for VPN authentication

  4. Support both Full Tunnel and Split Tunnel modes

Request

Please advise how we can achieve all of the above in a single IPsec setup, or if any architectural changes are required under the new Fortinet limitations.

Thank you.



1 REPLY 1
funkylicious
SuperUser
SuperUser
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"