Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Salonarus
New Contributor

Help with IPSEC VPN configuration using PPPoE

Hello everyone,

I’m having an issue with my IPSEC VPN. Basically, when I try to connect, the FortiClient doesn’t even show the loading percentage, and after a while the connection fails, saying the destination is unreachable.

Here’s how my network is set up so you can better understand the situation:
My ISP has provided me with a pool of IPs ranging from 193.x.x.2 to 193.x.x.5, with 193.x.x.1 as the gateway.
However, my public IP (the one used for internet access and bound to my PPPoE) is 82.x.x.9. So I suspect I might be behind a NAT imposed by my ISP (I tried contacting their support, but I couldn’t get a clear answer on this).

On my Fortinet FG100F, I have a “transparent” WAN2 interface configured with IP 0.0.0.0 and subnet 0.0.0.0. Then I created a WAN-type VLAN with PPPoE using the credentials provided by my ISP (the PPPoE is configured on the VLAN because my ISP requires a specific VLAN for WAN authentication).

I then added the PPPoE VLAN into the SD-WAN, set up a DDNS on that VLAN, and I can browse the internet without issues. From the outside, I can ping my public IP, and DDNS also works fine.

After that, I created my remote access IPSEC VPN (via FortiClient), binding it to the VLAN. But I just can’t figure out why the connection doesn’t even attempt to establish—it immediately fails.

Can anyone help me with this setup?

Additionally, I have another question: if I want to publish a machine with, for example, the IP 193.x.x.3, how should I handle the NAT? Basically, I’d like users to connect to 193.x.x.3 and be redirected to my internal machine at 192.168.1.10.

Thanks a lot in advance for your help!

1 REPLY 1
ozkanaltas
Valued Contributor III

 

Hello @Salonarus ,

 

Normally, if you can reach your public IP address from outside, you should also connect vpn. Maybe your ISP blocks a different port from outside connections. You can debug your ssl vpn connection with this document. Also, if you share your ssl vpn configuration with us, we can review your configuration and we give suggestion, or if there is a mistake, we can solve that problem. 

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPN-tunnels/ta-p/195955

 

Related your second question, you want to use DNAT for your internal service to access your service from outside. You can follow that document for DNAT configuration. 

 

https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/443514/configuring-vips

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors