Created on
12-15-2024
10:40 PM
Edited on
01-05-2026
10:10 PM
By
Jean-Philippe_P
| Description | This article describes how to access local LAN resources when connected to an IPsec dial-up full tunnel. Enabling split-tunneling is not allowed. |
| Scope | FortiGate, FortiClient. |
| Solution |
In this example, an IPsec Dial Up Full tunnel (DHCP over IPsec) is configured.
The local PC <10.190.3.113> can ping other local resources inside the same subnet. In this instance, the gateway <10.190.1.193> is reachable.
But once connected to the IPsec Dial-Up VPN, the IP 10.190.1.193 is unreachable.
To resolve this without enabling split-tunneling, select 'Enable Local LAN' under the FortiClient Phase1.
Once enabled, the local resources should be reachable now while connected to the IPsec VPN.
Additional Scenario: Windows clients are unable to access internal resources. Another scenario may occur where both macOS and Windows users can successfully connect using FortiClient, but only the Windows clients are unable to access or ping internal network resources. If this happens, try disabling, saving, and then re-enabling NAT Traversal in both. The Dial-Up VPN configuration on the FortiGate and within the FortiClient application.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.