Hi,
i want to replace my Windows 2019 RAS/VPN Server and the AlwaysOn VPN Setup.
In this Setup, i define the VPN Tunnels in Intune.
One Tunnel is a Device tunnel, the notebook can connect to a few servers only.
This is used for remote administration and for a user logon, if the user new to the notebook.
A Second Tunnel is for a User tunnel, after the notebook has established a Device tunnel and the user logon´s on, the user get´s his User tunnel.
=> After all, the machine has two VPN tunnels.
Now, i create this VPN/IKev2 tunnels in FortiGate 120G (7.4.9) with help of these articles
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Windows-IKEv2-native-VPN-with-machine-cert...
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/726232/windows-ikev2-native-...
The notebook will connect after reboot with a Device tunnel.
As soon the user logons on, Windows 11 gets the user tunnel up.
And now, both tunnel keep flapping (switchting from user tunnel <-> device tunnel)
Is this setup possible at all or will it never work with FortiGate?
Both tunnel assign an IP Range, split tunnel is enabled (i tried with split tunnel disabled).
But it´s not working
any advice, how to setup the tunnels?
thanks
Jürgen
Hi Jurgen
This may help.
https://video.fortinet.com/watch/forticlient-ipsec-vpn-pre-logon-configuration-and-demo
Thanks,
this look fine, but i would like to use the Windows 11 Enterprise native login.
It looks like two vpn tunnels to the same remote FortiGate is flapping.
Created on 10-15-2025 05:10 AM Edited on 10-15-2025 07:57 AM
After changing some of the Intune Settings (i set IKEv2 phase1/phase2 parameters to fixed values) and updating the machine tunnel and user tunnel policy, i have 2 client connecting properly.
But traffic is not passing from VPN Client through firewall into a SD-WAN tunnel to other Branch Office...
User | Count |
---|---|
2640 | |
1400 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.