Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
wailoon_ho
New Contributor

How to have fix ip for client

Hi all,

My company just bought a fortinet firewall for our HQ, all branch to connect HQ thru VPN. 

We need this VPN cause the POS system need to connect back to HQ database for synchronisation. 

 

But I have a problem, the POS is designed HQ and Client need to able to see each other. 

The Client can see the HQ database cause the IP is no change, but the HQ got problem to see the Client database cause everytime Client reconnect the VPN, the IP will changed.

 

I would like to ask, is there any way to fix the Client IP even the Client reconnect the VPN? 

Or any suggestion to solve this problem? 

2 REPLIES 2
ede_pfau
SuperUser
SuperUser

hi,

and welcome to the forums.

 

How does the Client connect to the VPN - via FortiClient, or via the branch Fortigate?

Assuming a software client:

usually, the client receives an IP address via DHCP over IPsec. This way, there can't be duplicate IP addresses around from clients. If you want to have a fixed address for each client, you can configure a static client IP address in the FortiClient. You will then have to make sure yourself that no address is used twice (using a list or such).

 

It would help if you specify the FortiOS version of the HQ FGT and (if applicable) the version of FortiClient in use.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
emnoc
Esteemed Contributor III

You have a  few options but if radius is used you can provide the framed-address attribute#8  to  just that client. This will ensure the client , upon authentications gets the same address ALL the time.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors