Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
freshfitz
New Contributor

Dialup VPN can't see all subnets

FortiOS 7.2.8

 

Main Lan 10.1.10.0

Dialup Users 10.20.30.0

Fortinet IP 10.1.10.1

 

Secondary LAN 192.168.0.0

 

Why can't dialup vpn user see all subnets, I have some IPs 192.168.0.0/24 on the same switch lan as 10.1.10.0

 

Dialup VPN users can browser 10.1.10.0 just fine but can't see 192.168.0.0, Since VPN takes 10.20.30.0 to 0.0.0.0. Shouldn't they see anything plugged into LAN port 1?

 

So LAN port 1 goes to switch, some machines have 10.1.10.0 and some have 192.168.0.0 on them, dialup vpn users can not see the 192.168.0.0 ip's

 

Rules

Static Route

10.0.20.0 lt2p interface

 

Dialup -> WAN1 - All All Lt2p Service

l2t.root -> LAN  -  Dialup Range to ALL

 

 

3 REPLIES 3
amrit
Staff
Staff

In case you are using a split tunnel  Dial-up VPN then you should add the other subnet in IPsec Phase1. Split tunnel subnets will be installed in the user's computer

 

Please refer to this article: article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-split-tunnel-For-IPsec-VPN/ta-p/192...

 

Config vpn ipsec phase1-interface 

edit <vpn tunnel name>

set ipv4-split-include "name of the subnet group"

end

end

If you are using the full tunnel, please make sure that destinations are allowed in the policy.

 

Amritpal Singh
RyanFItz
New Contributor

I'm using the windows dialup template so I do not have a split tunnel option. I tried the command line command and get an error. I tried to re-create the VPN using forticlient as that seems the only template that has split VPN option but I don't think Widows dialup with work with that VPN template

adimailig
Staff
Staff

Hi @freshfitz ,

By default, when you use Windows Native Dialup VPN it will be the default gateway of the PC (client).
May I verify if there is firewall policy allowing traffic from 10.20.30.0 to 192.168.0.0?
To further check traffic flow, please follow below troubleshooting guide.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...

For split tunneling, you may follow below guides
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Split-tunneling-on-L2TP-IPSEC-VPN-between/...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-split-tunneling-in-Windows-1...


Best Regards,

Arnold Dimailig
TAC Engineer
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors