Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pabaxe
New Contributor

Auto-Disable Forticlient VPN inside company network

Hello,

 

Is there a way to disable the Forticlient VPN when the computers are connecting from inside the company network?

 

I've seen some posts mentioning Local-in policies but I've had no success. We have a FortiGate 60F.

What I've done is create a policy with source address the internal network and destination the VPN IP, and set it to DENY, but it doesn't seem right.

 

Also is this something only done through CLI, or can it be implemented with Policies through the GUI?

 

17 REPLIES 17
pabaxe

This is an internal ip (192.168.1.2) so when i add it as dstaddr nothing changes, the users connect as normal.

And the thing is that this policy doesn't appear on Local-in-policies through the GUI.

srajeswaran

That means this is mapped to a public IP. You may check the VIPs configured on firewall or you can check your Forticlient to see the IP/URL address to which you are connecting to.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
pabaxe

Yes I know the public IP that the Forticlient connects to, and this is the External Address I was initially setting as dstaddr. But still doesn't appear/work.

srajeswaran

The Public IP is reachable via which interface? Can you specify that interface in the policy?

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Azureauto

Hey there, happy to help! For your first issue, it sounds like there might be a configuration glitch. Have you tried double-checking your commands and ensuring they're properly applied? As for the SSL VPN service, you might consider using a custom service with the appropriate port range specified. Hope this helps! If you need further assistance, feel free to reach out. Also, if you're interested, AzureAutoDetailing offers great car care services to help you unwind after tackling those tech challenges! :smiling_face_with_smiling_eyes:

Azure auto detailing
Azure auto detailing
amouawad
Staff
Staff

Are you trying to configure the FortiClients so that when they're connected to the corp network then the VPN is disabled?

 

Ifso you can do this if you have the FortiClients managed through EMS. EMS allows you to create 'on net' and 'off net' rules to dictate how FortiClient operates when it's on the corp network or off it.

 

There's multiple options available including the DHCP server, DNS server, subnet, default gateway or even the public IP that users would be on when connecting to the network.

 

ems.png

BellaEloise
New Contributor

Regarding CLI, you can also achieve this through command-line interface (CLI) using appropriate commands to configure the policy. However, using the GUI is generally more user-friendly and preferred for simpler configurations.

mle2802
Staff
Staff

Hi @pabaxe,

Is the SSL VPN set up with the same public IP as local user? I believe that most ISP should block traffic being NAT out and hit the same public IP again to prevent looping attack. You can also create a deny LAN-WAN policy with SSL VPN service and put it above regular Internet access policy.

Regards,
Minh

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors