I have several log entries in my VPN event manager for L2TP that state the client control connection finished. The problem I have is that there isn't an L2TP connection allowed on my Fortigate at the moment. How are L2TP connections being finished if they aren't allowed in the first place?
I guess these are VPN connection attempts to your FortiGate, and this is just normal from scan bots.
This cannot be blocked with regular firewall rule. If you don't want to see them anymore, either disable the existing IPsec tunnels (if you don't need them) or use "config firewall local-in-policy" to filter IKE connections from the GeoIP you want.
User | Count |
---|---|
2571 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.