Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor

IPsec VPNs ALWAYS route hop through DMZ interface IP address?

Fortigate firewall : 60D - Wifi

Firmware Version : v5.2.3,build670 (GA)

Operation Mode :  NAT

Ipsec vpn Client DHCP range :

VPN only can access the NAS,  IP:



When Client established the VPN connection and trying trace route to

The first hop is ALWAYS the IP address of the FortiGate' s DMZ interface, even though I have the FortiGate' s DMZ interface administratively down.

When I change the DMZ IP and trace route again , the first hop IP will be change accordingly 

When i change the DMZ IP to , the first hop IP will be change to WAN-1 IP (External IP for Internet)


Why the first hop is not the gateware IP address ? how can i fix this problem ?