Description | This article describes a possible cause for losing internet access after the user connects to a dial-up IPsec VPN configured with split tunneling enabled. |
Scope | FortiGate. |
Solution |
Solution:
Check the route print on the command line of the machine. If there is a 0.0.0.0/0 route pointing to the VPN, the client will lose internet connectivity.
Additionally, make sure the split tunnel address group under the VPN settings does not have a range. A particular IP or the whole subnet is preferred.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.