Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pnobels
New Contributor III

Forticlient local vlan routing instead of tunneling

Hi,

 

i'm wondering if there is a solution for the following concept...

 

Suppose user A is on site A in vlan A.  He/she wants to use a resource which is on site B and does this by using Forticlient vpn.  User A can also use any resource in vlan A on site A.

 

Suppose user A want to access a resource in vlan B of site A.  With an active Forticlient the result depends of what routing table info the user gets back after initiating the Forticlient vpn.  If the destination subnet of vlan B happens to be in there, then the trafic will get tunneled through the ssl vpn, and then back over an ipsec site-to-site vpn.  Which is kinda lame, as the data is actually local. 

 

You could ofcourse remove the destination subnet from the received routing table info, but this would mean that it would stop working for any other user at any other site...

 

Configuring the site-to-site vpn correctly is naturally also a very viable solution, but in this case study this is not the point...

 

So i'm looking for...  Is there a concept where a Forticlient is 'aware' of what local subnets are available.  Even if you have to define these manually in a text file for example and feed it to the Forticlient.  So the Forticlient knows after receiving the destination routing table info after initial connect, i can ignore received routing table entry x, y as these are actually local...

 

0 REPLIES 0
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors