FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
scampos
Staff
Staff
Article Id 367213
Description This article describes an alternative configuration to allow Internet connection in the Client using an IPsec LT2P dial-up VPN.
Scope FortiGate, Windows.
Solution

The split-tunnel feature is not well supported for a Native IPsec LT2P dial-up VPN configuration. However, if it is necessary to allow internet connectivity on the client side, it is possible to modify the Windows VPN configuration to not retrieve the Internet gateway from the Remote Network and use the actual machine adaptor.

 

The next example is done in Windows 11; for Windows 10 refer to the next article: Technical Tip: How to enable split-tunneling in Windows 10/11 (L2TP/PPTP VPN). - Fortinet Community.

 

  1. Open the search bar and look for the settings:
                                                   
    scampos_0-1736286342296.jpeg

     

  2. Go to Network & Internet and VPN:
                                                            
    scampos_1-1736286342297.jpeg

     

  3. Select the VPN connection and select Advanced Options:
                                                                            
    scampos_2-1736286342299.jpeg

     

  4. On the VPN selected, select Edit on More VPN properties:
                                                                       
    scampos_3-1736286342301.jpeg 
  5. In the Properties menu go to Networking, select the Internet Protocol Version 4 (TCP/IPv4), and select Properties:
                                                                                           
    scampos_4-1736286342803.jpeg

     

  6. Once in the Advance TCP/IP Settings, go to IP Settings and unselect the Use default gateway on remote network option:
                                                                                 
scampos_5-1736286342824.jpeg

 

Note:
This method will prevent the VPN from injecting the default route using the VPN tunnel interface. To enable split-tunneling to other local subnets, refer to Technical Tip: Split tunneling on L2TP/IPSEC VPN between FortiGate and Windows 10.