FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
pginete
Staff
Staff
Article Id 332979
Description

This article describes how to fix the inability to access the internet via dialup IPsec VPN tunnel when connected to WiFi.

Scope

FortiGate, FortiAP.

Solution

Internet via dialup using WiFi.png

 

The users cannot access the internet when connected via WiFi but can access the internet when connected via LAN. Below are the firewall policies configured on FGT1 and FGT2.

 

  • FGT1:

 

FGT1-policy-NAT-disabled.JPG

 

FGT2:

 

FGT2-policy.JPG

 

To fix it, add an IP address on the VPN tunnel interface of both FGT1 and FGT2.  

 

FGT1 tunnel IP.JPG

 

FGT2 tunnel IP.JPG

 

Enable the NAT in the firewall policy of FGT1 to fix the issue.

 

FGT1-policy-NAT-enabled.JPG

 

Contributors