HI, I have setup a client to site vpn in my firewall. Now I have created different IPsec VPNs for different departments but they are using the same remote gateway. I want to control the environments that different departments need to access. The issue is that once I enable the different policies for the different groups, the forticlient cannot connect. But once I disable all the policies and enable only one policy, I am able to connect and access my network. What could be the issue?
hm maybe if you enable those policies no one matches the vpn traffic? Without (matching) policy the vpn will not connect. IPSec Debug log on cli on your FGt will show you a corresponding error upon connecting in this case.
I control different vpns (S2S as well as C2S) by simply using the corresponding vpn interface as source interface and the corresponding vpn subnet as source address(es). Works fine here.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
OK, thanks for your response. Now tell me, how would you go about configuring a C2S IPsec vpn for an organization and then separate each department so that they can access only the networks they have the right to access?
would do that per department. Each department has a C2S to HQ. So all ppl at a department can dial in using that C2S of their department. This will require using peer ids at the remote gw to have he FGT use the right tunnel. Then you could do mode config to distribute ip adresse to clients and then you could use that tunnel interface plus subnet for policies...
I here have C2S to our HQ for Homeoffice, for the it dept and some more and they are done that way and it works fine.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
761 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.