first all, I'm not good at English, I don't know if I expressed exactly.
Firewall:Fortigate-200A, Firmware Version:3.00
The remote user can access to the HQ LAN inside firewall by PPTP dial up or Forticlient IPSec client. The remote host has the IP address segment same with the LAN host inside the firewall.
but I have a question. when VPN tunnel is built, how can I initiate access to the remote host?
I can not ping through the remote host, can not access remote host by Windows remote desktop, etc. Just like the remote host are not in the LAN.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
hi,
and welcome to the forums.
Well, it is not in the LAN. So the FGT has to do routing to direct traffic to the client.
This is a technical peculiarity of dial-in VPNs. If you establish a client tunnel and look at the Routing Monitor you will see that the FGT has inserted a route between the FGT and the client automatically. But, both addresses are restricted to this one address by the '/32' netmask. So, traffic directly from the FGT can reach the client, and vice versa, but a host on the LAN cannot.
You cannot 'override' this automatic route as it already has the highest priority and lowest distance.
The same question pops up here in the forums regularily, and the answer is always the same: a client connection is not a site-to-site connection.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.