Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Access from VPN Client to DMZ Server

Hi all. We just implemented a new proxy server in our DMZ. We can access it from internal just as supposed, everything fine. Now we have some people with FortiClient on their machines and they can' t reach anything in our DMZ. LAN: 10.27.56.0/24 VPN: 10.27.56.0/24 via DHCP Relay (needed for SAP stuff, not changeable) DMZ: 10.27.63.32/27 DMZ port of Fortigate: 10.27.63.36 Proxy: 10.27.63.39 I can' t reach anything like 10.27.63.43 when I' m dialed in via IPSec VPN. I tried the following: - Encryption policy from LAN to DMZ - static route - changed the setting " Internet Browsing" in Phase 2 setting around - added the DMZ to the Remote Network in FortiClient Long story short: I can not connect to anything in the DMZ when I' m connected via VPN. It' s the same IP Range like the LAN so it really should work...! It would be great if anybody gave me some hints what I could check. New proxy runs so smooth and I want it to go productive very soon... Thanks for any comment... stephan
11 REPLIES 11
Not applicable

What you want isn' t really possible... and also a bit unlogical.
Hm :-/ Well... I did not setup this, I have to live with it. I don' t really know why 2 DMZs where made. It may make sense to think about creating one DMZ and use one port for Internet only. I think that would make life easier.
But what you might try is to allow internet browsing from the FG. Add 0.0.0.0 or something to the FC remote network, that might do the trick.
Ok, adding 0.0.0.0 as remote network is no problem, just tried that. Even a traceroute will then go over the fortigate, but it fails for the known Reasons. How would I " allow Internet Browsing from the FG" ? Is that the option in Phase two on IPSec? Many thanks for your help guys! stephan
Not applicable

*bump* Help! Any ideas or advice?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors