FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ddeguzman
Staff
Staff
Article Id 364819
Description This article describes how to access local LAN resources when connected to an IPsec dialup full tunnel. Enabling split-tunneling is not allowed.
Scope FortiGate, FortiClient.
Solution

In this example, an IPsec Dial Up Full tunnel (DHCP over IPsec) is configured.

 

FortiGate_IPsecConfig.JPG

 

Related article:

Technical Tip: IPsec dial-up full tunnel with FortiClient

 

The local PC <10.190.3.113> can ping other local resources inside the same subnet. In this instance, the gateway <10.190.1.193> is reachable.

 

LocalPC_IP.JPG

 

But once connected to the IPsec Dial-Up VPN, the IP 10.190.1.193 is unreachable.

 

LocalPC_NotPingable.JPG

 
The traffic is being routed through the tunnel instead. 

 

FortiGate_Sniffer.JPG

 

To resolve this without enabling split-tunneling, select 'Enable Local LAN' under the FortiClient Phase1.

 

FortiClientEnableLocalLan.JPG

 

Once enabled, the local resources should be reachable now while connected to the IPsec VPN.

 

Pingable_WithIPsecVPN.JPG

 

Related article:
Technical Tip: FortiGate IPSec VPN resource list

Contributors