Created on
11-29-2023
09:57 PM
Edited on
11-27-2024
10:35 PM
By
Jean-Philippe_P
| Description |
This article describes the case when connecting to the L2TP tunnel, by default, all traffic will be routed to the tunnel. As a result, if the L2TP tunnel has been created with the IPSec wizard on the FortiGate, the endpoint will not be able to connect to the Internet:
|
| Scope | FortiGate. |
| Solution |
In most cases, L2TP has full-tunneling enabled. It is possible to disable this option either on the local PC, or globally on the FortiGate.
The CLI configuration equivalent for this is:
config firewall policy edit 5 set name "L2TP-to-Internet" set srcintf "l2t.root" set dstintf "virtual-wan-link" set action accept set srcaddr "all" set dstaddr "all" set schedule "always" set service "ALL" set nat enable next end
As a result, the endpoint should now be able to connect to the Internet while connecting to the L2TP tunnel:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.