Description | This article describes configuring IPsec remote access via FortiClient with full tunneling. |
Scope | FortiGate v7.0, v7.2, and above. |
Solution |
Follow the steps below to enable full tunneling for IPsec remote access via FortiClient:
Note: If split tunneling is configured and needs to be disabled to allow full tunneling, this can also be done using the CLI by disabling the split tunneling feature in the phase1 settings of the tunnel using the following commands:
config vpn ipsec phase1-interface edit <phase1 name> unset ipv4-split-include end
CLI configuration example:
Phase1.
config vpn ipsec phase1-interface
Phase2.
config vpn ipsec phase2-interface
Note: Configuring changes (i.e. changing from split to full-tunnel) in the IPsec VPN while a user/s is connected, will disconnect them and will need to reconnect.
For enabling split tunnel: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.