Hi Guys,
We need to create two profiles for Remote VPN access on Fortigate
FULL access:
Laptop users have all ports open to LAN (for RDP/SMB/HTTP(s) traffic to servers) and uses UTM-10.20.1.254 as a gateway
the problem is when i configured VPN profile there was no way to assign gateway, how i can do this?
At the moment laptop gets 10.20.3.2 and his gateway is 10.20.3.3
RDP access:
Users has only access to their workstations in the office. This is somehow already sorted by allowing only RDP and DNS in the Remote to Local policy
No gateway to be assigned, currently it automatically assign 10.20.3.3
Please see attached diagram
Kind Regards
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
akrohn wrote:
If I understood correctly, your FULL User use your UTM as default gateway to Internet ?
Yes, it's a gateway/proxy to internet and also a gateway to a production systems through a separate fiber line.
akrohn wrote:
But for what do you need the VPN Remote Access ?
RDP profile is to allow people work from home. They need to access their workstations from their home PCs, nothing else.
FULL is for Laptop users, so no matter where they are they can work as they are in the office. There are different subnets from other site-to-site VPNs and connection to two data centers
Honestly, Fortigate is extremely terrible when one compares it to bog standard Windows Server VPN (especially AlwaysON VPN) setup.
Just deploy Windows VPN & you will have zero problems
I done that I never looked back at Fortigate issues
Seb
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.