Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

IPSec VPN Remote Access

In fortigate v7.6 the SSL VPN is retired so i create IPSec VPN for remote access.

Tested using my android phone using native android vpn client and the vpn connection is working fine.

But if i use forticlient vpn both on my android or my windows then the VPN is connected but can't access to anywhere.

In forticlient VPN client i see i got the ip address from the fortigate 10.18.200.100 but the gateway is 10.18.200.101

Screenshot 2025-07-03 121031.png

Screenshot 2025-07-03 121057.png

From where the forticlient get the gayteway 10.18.200.101?

Here my IPsec vpn setting at fortigate.

Screenshot 2025-07-03 120954.png

1 REPLY 1
filiaks1
Contributor II

By looking at FortiGate Dial-Up VPN Configuration then client address range 1 ip address is provided to the Fortigate that is used for gateway match. 

 

Better check your routing , securiry policy etc. See Re: Dial-up IPsec VPN Issues with Windows Cloud PC - Fortinet Community where someone seems to have similar issue.

 

Also using nat traversal and IPSEC tcp and loopback could be beneficial and as I mentioned in the other case see with flow debug/packet capture if traffic is reaching the firewall as to know if the vpn client is the issue (not sending it to the FW) or if the FW needs better review.

 

Dialup IPsec VPN using custom TCP port | FortiGate / FortiOS 7.6.3 | Fortinet Document Library

Best practice when IPSec VPN is bound to ... - Fortinet Community

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors