Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ferdo
New Contributor

Forti 600C : How to set ssl VPN subnet default gateway

Hi, Can anyone tell me how to set the default gateway of my SSL VPN subnet. Regards
14 REPLIES 14
rwpatterson
Valued Contributor III

I would assume you are using tunnel mode. The FGT will do that automatically. Just make sure that the interface IP address falls within the SSL VPN IP range.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Ferdo

Hi rwpatterson, Thank you for answering me. Of course the IP address is in the address range of SSL VPN. The client connected via VPN can not access resources located in DMZs. For the client accesses to resources in the DMZ, I must first create a route on the PC to the DMZ. Can you tell me how to not have to create route every time a client connected via VPN to access the DMZ ? Thank you very much Regards Ferdo
rwpatterson
Valued Contributor III

Are you using the Forticlient product or the SSL VPN client product?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Ferdo

Hi rwpatterson, Some users use the FortiClient product and others connect with their Internet browser. If there is no solution, how can I run the script to create the route to my DMZ LAN when establishing the VPN tunnel ? Thank you very much Regards Ferdo
rwpatterson
Valued Contributor III

I don' t see how it' s not working for you. I can connect to over a dozen remote subnets through my SSL connection without having to define a single thing. Are you using split tunneling?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Ferdo

Hi, My problem is the following: My LAN is 10.1.0.0/16 VPN SSL subnet is 10.1.200.0 with 10.1.200.254 as default gateway. When I connect via VPN, I get an IP address on the LAN 10.1.200.0 and I can access all the resources of LAN 10.1.0.0/16. But to access a server on my DMZ (192.168.117.0) I have to create a route on the PC like this: route add 192.168.117.0 mask 255.255.255.0 10.1.200.254 metric 1 Do you understand my problem please ? Regards Ferdo
rwpatterson
Valued Contributor III

Make the SSL VPN subnet unique to your organization. Don' t overlap another interface' s subnet space.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Ferdo

Hi, I do not quite understand. Can you explain what you mean by " Don' t overlap another interface' s subnet space" please ? Thank you Regards
rwpatterson
Valued Contributor III

ORIGINAL: Ferdo My LAN is 10.1.0.0/16 VPN SSL subnet is 10.1.200.0 with 10.1.200.254 as default gateway. When I connect via VPN, I get an IP address on the LAN 10.1.200.0 and I can access all the resources of LAN 10.1.0.0/16.
Although you and I know that 10.1.200.0/24 is a different network than 10.1.0.0/16, it still falls inside of the 10.1.0.0/16 umbrella. This sometime confuses the firewall. Change your SSL VPN scope to something like 192.168.200.0/24. This is outside of the LAN scope altogether. After you make this change and update the policies and address entities, let' s see how we fare.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors