Hi all,
My company just bought a fortinet firewall for our HQ, all branch to connect HQ thru VPN.
We need this VPN cause the POS system need to connect back to HQ database for synchronisation.
But I have a problem, the POS is designed HQ and Client need to able to see each other.
The Client can see the HQ database cause the IP is no change, but the HQ got problem to see the Client database cause everytime Client reconnect the VPN, the IP will changed.
I would like to ask, is there any way to fix the Client IP even the Client reconnect the VPN?
Or any suggestion to solve this problem?
hi,
and welcome to the forums.
How does the Client connect to the VPN - via FortiClient, or via the branch Fortigate?
Assuming a software client:
usually, the client receives an IP address via DHCP over IPsec. This way, there can't be duplicate IP addresses around from clients. If you want to have a fixed address for each client, you can configure a static client IP address in the FortiClient. You will then have to make sure yourself that no address is used twice (using a list or such).
It would help if you specify the FortiOS version of the HQ FGT and (if applicable) the version of FortiClient in use.
You have a few options but if radius is used you can provide the framed-address attribute#8 to just that client. This will ensure the client , upon authentications gets the same address ALL the time.
PCNSE
NSE
StrongSwan
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.