Description | This article describes that from the Client host, the gateway and the DHCP server would be the next available IP address when Dialup VPN is connected. |
Scope | FortiGate. |
Solution |
When the client user1 tries to connect to Dialup VPN from FortiClient, the first thing that the user1 is confused about is checking in CMD: 'ipconfig ' or 'route print'.
To find the virtual adaptor's default gateway and DHCP Server the following IP address.
The following Client user2 would get the IP address 192.168.100.2, and the default gateway is 192.168.100.3.
It would not be very clear if 192.168.100.1 ping 192.168.100.2, the ICMP should be sent to FortiGate or user2.
As the Dailup VPN is the point-to-point tunnel:
147 # fnsysctl ifconfig Dialup
All traffic would pass directly through the FortiGate. FortiGate will not check the gateway, only forward the traffic based on the destination. To allow dialup VPN to communicate, a dialup to dialup policy needs to be created.
Test RDP to 192.168.100.2 results in connecting to user2 successfully.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.