Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
UkWizard
New Contributor

Forticlient using seperate IP subnet

Hi all, I am struggling to get the forticlient working when using a ip set in the " aquire ip" . it either will not work at all or will connect but will not allow me to talk to anything. The vpn is working fine as such without using this ip option. But ideally i would like external vpn users to have a seperate IP range for them, rather than using the firewalls, or an internal pool (which i also cannot get going). If anyone knows how to do this, could you please give me steps on the firewall and the forticlient on how to achieve this. Thanks in advance.[>:]
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
5 REPLIES 5
skyhigh
New Contributor

Works fine with FortiCilent build 202 as long as the IP is in a different subnet than the destination subnet. You might want to try build 206 which is now available by logging in to the support website -- this is the current recommended FortiClient release.
Fortinet Technical Support
Fortinet Technical Support
vanc
New Contributor II

build 206 or 207 is recommended. it fixed several routing bugs over build 202.
Not applicable

the problem is the missing proxy arp function of the fortigate hosts with internal lan ips do not use the standard gateway if the target seams to be in the same subnet you can see this by using a sniffer so the box does not reply to arp questions for the virtual ips
UkWizard
New Contributor

But surely Your VPN client should reply to the Arp, as it has the actual address, rather than the fortinet itself. Unless the clients mac is not seen on the network i suppose. So how do you get around this ? cos curely this would prevent all traffic from working within this same subnet ?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
vanc
New Contributor II

Arp packet is only brocasted on the local network. So FortiClient sitting on a remote network can not answer the Arp request. But if you let FortiClient to acquire an IP not in the same subnet as the remote network, it should work. But DHCP over IPSec only works with FortiOS 2.80 which is still not released.
Labels
Top Kudoed Authors