Hello everyone,
I'm kind of curius at this point if there is any solution to this problem:
I have a Fortigate 60f (v7.0.10) setup to handle my ipsec VPN connections. There are site to site and end to site tunnels configured and working. The Fortigate is directly connected to the internet with a public IPv Adress.
One of the end to site VPN's is using the old Shrew Soft VPN Client and I want to switch to FortiClient. After a few frustrating failed tries to set up the tunnel I realized all the internet connections I tried used DS-Lite. When I connected my notebook with the FortiClient (v7.0.7.0345) installed over the SIM card it immediatly worked.
I saw for SSL VPN there is an extra configuration implemented to accept sessions over DS-Lite https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/766455/dual-stack-ipv4-and-i... .
Is there anything similar for ipsec VPN's or am I missing something?
The config which worked with FortiClient over the SIM card was installed over the wizard with the template "Remote Access", "Client-based", "FortiClient".
If you need any more information please let me know.
Thanks
Lukas
What is DS-Lite?
Sounds like it might be a NAT issue? Check your VPN settings. For NAT Configuration, select The remote site is behind NAT.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.