FortiOS 7.2.8
Main Lan 10.1.10.0
Dialup Users 10.20.30.0
Fortinet IP 10.1.10.1
Secondary LAN 192.168.0.0
Why can't dialup vpn user see all subnets, I have some IPs 192.168.0.0/24 on the same switch lan as 10.1.10.0
Dialup VPN users can browser 10.1.10.0 just fine but can't see 192.168.0.0, Since VPN takes 10.20.30.0 to 0.0.0.0. Shouldn't they see anything plugged into LAN port 1?
So LAN port 1 goes to switch, some machines have 10.1.10.0 and some have 192.168.0.0 on them, dialup vpn users can not see the 192.168.0.0 ip's
Rules
Static Route
10.0.20.0 lt2p interface
Dialup -> WAN1 - All All Lt2p Service
l2t.root -> LAN - Dialup Range to ALL
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
In case you are using a split tunnel Dial-up VPN then you should add the other subnet in IPsec Phase1. Split tunnel subnets will be installed in the user's computer
Please refer to this article: article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-split-tunnel-For-IPsec-VPN/ta-p/192...
Config vpn ipsec phase1-interface
edit <vpn tunnel name>
set ipv4-split-include "name of the subnet group"
end
end
If you are using the full tunnel, please make sure that destinations are allowed in the policy.
I'm using the windows dialup template so I do not have a split tunnel option. I tried the command line command and get an error. I tried to re-create the VPN using forticlient as that seems the only template that has split VPN option but I don't think Widows dialup with work with that VPN template
Hi @freshfitz ,
By default, when you use Windows Native Dialup VPN it will be the default gateway of the PC (client).
May I verify if there is firewall policy allowing traffic from 10.20.30.0 to 192.168.0.0?
To further check traffic flow, please follow below troubleshooting guide.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
For split tunneling, you may follow below guides
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Split-tunneling-on-L2TP-IPSEC-VPN-between/...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-split-tunneling-in-Windows-1...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.