Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mcegielka
New Contributor

IP address assignment in policy-based VPN.

Hi all!

 

I'm currently using FortiGate 800C with firmware v5.2.1 in transparent mode and created one Ipsec VPN tunnel. Is it possible to automatically assign IP addresses to VPN clients with FortiClients? I've checked "set assign-ip-from", "set mode-cfg" and "set dhcp-ipsec", but all seem unavailable in policy-based VPNs.

 

Thanks!

 

1 Solution
emnoc
Esteemed Contributor III

Your in transparent mode? PB-vpn are defined by policies for src/dst subnets. Never heard or any fortigate  capable of operating a vpn-server in PB-vpns.

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
2 REPLIES 2
emnoc
Esteemed Contributor III

Your in transparent mode? PB-vpn are defined by policies for src/dst subnets. Never heard or any fortigate  capable of operating a vpn-server in PB-vpns.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
mcegielka

Hello, and thanks for answer.

 

emnoc wrote:

Your in transparent mode? PB-vpn are defined by policies for src/dst subnets. Never heard or any fortigate  capable of operating a vpn-server in PB-vpns.

 

I would call FG unit with defined PB-VPN a vpn-server :) Did you mean dhcp-server?

 

I've found following setting:

config system settings  set dhcp-proxy enable but still don't see any chance of using it in PB-VPN.   To add to confusion I've found following description of DHCP over Ipsec: http://docs-legacy.fortinet.com/fos50hlp/52/index.html#page/FortiOS%25205.2%2520Help/phase2.103.14.h...
DHCP-IPsec Select this option if the FortiGate unit assigns VIP addresses to FortiClient dialup clients through a DHCP server or relay. This option is available only if the Remote Gateway in the Phase 1 configuration is set to Dialup User and it works only on policy-based VPNs.
 
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors