Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RocketDog
New Contributor

Forticlient Network Lockdown IPSEC VPN

Hello,

My company has FortiClient installed on windows laptops, managed by EMS. We currently use always-on IPSec.

We now want our laptop to communicate throught VPN only, no LAN or off-VPN internet communication whatsoever.

How can we achieve this ? Network Lockdown only works with SSL VPN

I tried making exceptions in the Windows Defender Firewall for Forticlient.exe (and others) without any success.

Any hint would be greatly appreciated !

 

Thank you

2 REPLIES 2
dbhavsar
Staff
Staff

Hello @RocketDog ,

 

This can be helpful, https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPSec-dial-up-full-tunnel-with-FortiClient...
So based on the policy you can control the traffic if the split tunnel is disabled.

DNB
RocketDog

Hi, thank you for your reply.
In deed that's how my setup is right now. 

My goal is to block all LAN/internet communication if the IPSEC VPN is not connected. 

There is an option to do that with SSL_VPN (Network Lockdown), but i'm struggling to do it using IPSec. I assume there could be a Windows Defender Firewall configuration to do, but didn't have any success so far.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors