FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
amahdi
Staff & Editor
Staff & Editor
Article Id 307034
Description This article describes a possible cause for losing internet access after the user connects to a dial-up IPsec VPN configured with split tunneling enabled.
Scope FortiGate.
Solution
  • Upon configuring dial-up settings and enabling split tunneling, the user has to select accessible networks:

Dialup settings.jpg

 

  • As shown in the above screenshot, the user can select all (0.0.0.0/0) as a member of the accessible network group configured under the VPN settings.

  • So, upon connecting to the VPN, the user will lose internet connectivity since there is no policy configured from the VPN tunnel to the WAN interface, as the user has enabled split tunneling to route only internal traffic through the tunnel.

Solution:
Double-check and confirm that only the desired subnets are specified under the VPN-accessible network settings.

 

Check the route print on the command line of the machine. If there is a 0.0.0.0/0 route pointing to the VPN, the client will lose internet connectivity.

 

Additionally, make sure the split tunnel address group under the VPN settings does not have a range. A particular IP or the whole subnet is preferred.

 

Related article:

Technical Tip: Enable split-tunnel For IPsec VPN