Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Red_and_blue
New Contributor II

IPSEC Dial-up VPN two scenarios

ok trying to have secure VPN connections for two different type of users.  


We currently have a Fgate 60F V7.2.1; Windows AD environment; Fclient 7.2.5; EMS on Windows server

 

We can't use the SSL VPN.

 

I have two sets of users

1/ home PCs using the fclient free version; IPSEC VPN (IKE V1) then they RDP to their desktops; only RDP allowed in the firewall policy

2/ work supplied laptops using fclient with EMS; to have full normal access; currently using SSL however we have to move away from SSL. 

 

Questions are

A: is 1. a silly thing to do.  Should we just bite the bullet and buy bad laptops that are locked down to only allow the VPN and nothing else. Can we have a home PC connect securely, only allow them to RDP to their desktop; is this a massive security risk.  

B: can I have two IPSEC dialups set up on the Fgate? Can anyone share a decent doc that actually explains what all the options do or even better says choose these ones.  I've created a second IPSEC dialup using IKE2 and can't get it to work.  Before I go down the debug or raising a job I just thought I should check that what I'm trying is sensible. 

 

thanks in advance.

Red

 

 

10 REPLIES 10
pondich7
New Contributor

It's easier to set a source in the client's phase 2 and leave 0s everywhere else. That way the hub can leave add route enabled, which makes upkeep easier unless you run some form of dynamic routing over the tunnel.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors