Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jba
New Contributor

Dual IKeV2 VPN Tunnel like MS AlwaysOn with Machine tunnel AND User Tunnel (is it possible)

Hi,

i want to replace my Windows 2019 RAS/VPN Server and the AlwaysOn VPN Setup.

In this Setup, i define the VPN Tunnels in Intune.

 

One Tunnel is a Device tunnel, the notebook can connect to a few servers only.

This is used for remote administration and for a user logon, if the user new to the notebook.

 

A Second Tunnel is for a User tunnel, after the notebook has established a Device tunnel and the user logon´s on, the user get´s his User tunnel.

 

=> After all, the machine has two VPN tunnels.

 

Now, i create this VPN/IKev2 tunnels in FortiGate 120G (7.4.9) with help of these articles

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Windows-IKEv2-native-VPN-with-machine-cert...
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/726232/windows-ikev2-native-...

 

The notebook will connect after reboot with a Device tunnel.

As soon the user logons on, Windows 11 gets the user tunnel up.

 

And now, both tunnel keep flapping (switchting from user tunnel <-> device tunnel)

 

Is this setup possible at all or will it never work with FortiGate?

 

Both tunnel assign an IP Range, split tunnel is enabled (i tried with split tunnel disabled).

But it´s not working

 

any advice, how to setup the tunnels?

 

thanks

 

Jürgen

2 REPLIES 2
AEK
SuperUser
SuperUser

AEK
jba
New Contributor

Thanks,

this look fine, but i would like to use the Windows 11 Enterprise native login.

It looks like two vpn tunnels to the same remote FortiGate is flapping.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors