Hi,
i'm wondering if there is a solution for the following concept...
Suppose user A is on site A in vlan A. He/she wants to use a resource which is on site B and does this by using Forticlient vpn. User A can also use any resource in vlan A on site A.
Suppose user A want to access a resource in vlan B of site A. With an active Forticlient the result depends of what routing table info the user gets back after initiating the Forticlient vpn. If the destination subnet of vlan B happens to be in there, then the trafic will get tunneled through the ssl vpn, and then back over an ipsec site-to-site vpn. Which is kinda lame, as the data is actually local.
You could ofcourse remove the destination subnet from the received routing table info, but this would mean that it would stop working for any other user at any other site...
Configuring the site-to-site vpn correctly is naturally also a very viable solution, but in this case study this is not the point...
So i'm looking for... Is there a concept where a Forticlient is 'aware' of what local subnets are available. Even if you have to define these manually in a text file for example and feed it to the Forticlient. So the Forticlient knows after receiving the destination routing table info after initial connect, i can ignore received routing table entry x, y as these are actually local...
Hi Pnobels,
I agree with the traffic flow. The resource for vlanB might be local from the physical point of view but since the layer 3 broadcast domain resides at site B, traffic would be routed on longest prefix match. You may consider editing the XML configuration in FortiClient to manually exclude subnets from being tunnelled.
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.