Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Stranger1
New Contributor

Dial-up IPsec VPN Issues with Windows Cloud PC

I have a dialup IPsec VPN account on Fortigate firewall. When I use my laptop to connect to VPN using the firewall credentials, I can successfully connect and then RDP to the remote servers.

When I use the same connection and credentials from my Windows Cloud PC 365, although the VPN gets connected successfully but I am not able to access any of the remote servers via RDP.

There is no change in the VPN connection. It works absolutely fine from laptop but does not work from Cloud PC.
Cloud PC does not allow ping, telnet or tracert as per Microsoft policies.

When I do "route print" I can see exactly same results on my laptop and on my cloud PC for destination network and IP assigned to me via VPN. (with of course a different IP from VPN range)

 

My fortigate FortiOS is 7.6.3 which does not allow SSL VPN.

 

I have another Fortigate with FortiOS 7.4.8 with SSL VPN configured.

I am able to connect SSL VPN and RDP to remote servers successfully.  

 

Is there any workaround/fix for FortiOS 7.6.3 for Dial-up IPsec VPN?

 

Thanks.

2 REPLIES 2
filiaks1
Contributor II

I see what you mean SSL VPN to dial-up VPN migration | FortiGate / FortiOS 7.6.3 | Fortinet Document Library as you are using 2GB RAM version VM and a trial?

 

If so better use something with more RAM. Outside of that if 1 PC works and cloud one does not then this seems like not a firewall issue. See Different methods to capture packets for ... - Fortinet Community  and make certain that you see the RDP traffic from the firewall as you may have security rules in place that stop the cloud PC (who knows) so use policy trace and debug flow to see and if need pcap traffic capture. If the debug does not show anything then it could be for some reason the cloud PC to not use the VPN tunnel to send traffic. 

 

Trace which firewall policy will match ba... - Fortinet Community

Enable Policy Trace in Debug Flow - Fortinet Community

Using the debug flow tool | FortiGate / FortiOS 7.6.3 | Fortinet Document Library

Debugging the packet flow | FortiGate / FortiOS 7.6.3 | Fortinet Document Library

 

Also review if you want the forticlient agent logs and agentless VPN and if NAT traversal is needed or not as maybe the Cloud PC has different path.

 

Agentless VPN 7.6.3 | FortiGate / FortiOS 7.6.0 | Fortinet Document Library

How to troubleshoot IPsec SAML Dial UP tu... - Fortinet Community

Exporting the log file | FortiClient 7.4.3 | Fortinet Document Library

FortiClient as dialup client | FortiGate / FortiOS 7.6.3 | Fortinet Document Library

filiaks1
Contributor II

Also see IPsec Client VPN IKEv2 Split-Tunneling - Fortinet Community as many people seem to be facing similar issue because of the change.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors