Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rpall
New Contributor

Companys PublicIP shared over VPN

Hi Folks!

 

i have a special problem, we want that our user´s can use our public ip over vpn, but i don´t find any options in our fortigate FW60.

 

has anyone the same? maybe someone can help.

 

thanks a lot

1 Solution
Yurisk

Then proceed according to this example and it will work: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disabling-Split-Tunnel-configuration/ta-p/... 

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.

View solution in original post

Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
4 REPLIES 4
Yurisk
SuperUser
SuperUser

Do you mean by "use our public ip over vpn" that users will connect with FOrticlient to the Fortigate and then browse to the Internet via this tunnel? If so, then it is easy - do not enable Split Tunneling in SSL VPN settings and create additional Security rule - from ssl.root interface to WAN/Internet interface with NAT enabled.

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
rpall
New Contributor

yes, we have the callenge that our company users are in homeoffice, but the need our public ip, for working

Yurisk

Then proceed according to this example and it will work: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disabling-Split-Tunnel-configuration/ta-p/... 

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
sw2090
Honored Contributor

you should differ: do you want  the complete traffic of your users including internet to go gout via your public ip? Then simly do not enable split tunneling.

 

Do you want to enable your users to access some external services via the vpn that are limited to your company's public ip? Then you need to add that to the split tunneling and set a policy to allow that using nat with your public ip...

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors