Description | This article describes how to access local LAN resources when connected to an IPsec dialup full tunnel. Enabling split-tunneling is not allowed. |
Scope | FortiGate, FortiClient. |
Solution |
In this example, an IPsec Dial Up Full tunnel (DHCP over IPsec) is configured.
Related article: Technical Tip: IPsec dial-up full tunnel with FortiClient
The local PC <10.190.3.113> can ping other local resources inside the same subnet. In this instance, the gateway <10.190.1.193> is reachable.
But once connected to the IPsec Dial-Up VPN, the IP 10.190.1.193 is unreachable.
To resolve this without enabling split-tunneling, select 'Enable Local LAN' under the FortiClient Phase1.
Once enabled, the local resources should be reachable now while connected to the IPsec VPN.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.