Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
itx86
New Contributor

FortiClient Default Gateway IPsec

Hello guys, I am facing the following challenge and can't get any further. I hope you can help me.

 

I want to connect a VPN between a virtual server (hosted Windows Server 2016) and a data center.

The virtual server has no VPN capability. With FortiClient I was able to establish the connection to the data center via IPSec,

but it takes the IP of the data center when it goes out to the Internet. What do I have to change or how do I get it that he keeps his IP? Or is there another way, I have a FortiGate 50E in the datacenter. Thank you very much for your help.

1 Solution
SteveG
Contributor III

Thanks for the screenshot, it really helps. Under "Accessible Networks" enter the network range you want to access via the VPN, for example 10.0.0.0/8.

 

This doc provides an example config

 

https://kb.fortinet.com/kb/viewContent.do?externalId=FD36253

 

The part you need is 

    set ipv4-split-include "Internal_Network"     /* Local protected network that the remote dial-up IPsec clients reach */    

View solution in original post

5 REPLIES 5
SteveG
Contributor III

If I understand what you're asking you need to configure the VPN for Split Tunneling and specify the CIDR ranges you'd like to send via the FortiClient VPN.

itx86
New Contributor

Hi Steve, thank you so much for the answer. Yes, I checked that as a test, but nothing has changed. Where do I set the CIDR? What must I enter, can you please give me an example. Do I have to consider or change the configuration of IPv4 Policy or Forticlient App? (screenshot in the attachment)

Thanks for your help.

 

SteveG
Contributor III

Thanks for the screenshot, it really helps. Under "Accessible Networks" enter the network range you want to access via the VPN, for example 10.0.0.0/8.

 

This doc provides an example config

 

https://kb.fortinet.com/kb/viewContent.do?externalId=FD36253

 

The part you need is 

    set ipv4-split-include "Internal_Network"     /* Local protected network that the remote dial-up IPsec clients reach */    

itx86
New Contributor

Thank you, that was the solution. You saved my day, thank you Steve. :-))

SteveG
Contributor III

Excellent :)

Labels
Top Kudoed Authors