Is it possible to bind users to a specific IP with IPsec VPN?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Please see this KB article which would be helpful http://kb.fortinet.com/kb....do?externalID=FD37351
You seem to be a friend of few words. Could you please elaborate on your question. Is this about address assignment of IPsec VPN clients? FortiClient or AnyConnect, that is, mode config or not?
Less guessing, more answers.
Hi.
Yes, I have a IP-Pool which are given to IPsec VPN Clients. I want to achieve to assign unique IP adresses to Fortigate VPN-Users or VPN-Clients if possible. "User1" always gets 192.168.10.45 etc. I'm using the Fortigate VPN Client.
PS: Doesn't know Cisco AnyConnect works at all with Fortigate?!? The Client doesn't have enough options to configure.
Hi,
Please see this KB article which would be helpful http://kb.fortinet.com/kb....do?externalID=FD37351
Hi. Wont work for me :o
Have the following Interfaces in my VPN vdom:
+Port1 (VPN Ingress) type:physical IP 1.2.3.4
-+ IPsec_VPN created by Wizard type:VPN_Tunnel
+Port2 (VPN Egress) type:physical
-+VLAN100 (in which VPN Target Network is) type:VLAN IP 192.168.0.1
I've now configured the DHCP on VLAN100, because I only can configure a DHCP Server on a Interface which has an IP in the Subnet of the DHCP Range (192.168.0.100-200).
If I chose in FortiClient IPsecDHCP, The Phase2 seemes to work, but the connection doesnt come up. Because I guess no IP will be assigned.
Deactivating "Mode Config" in the VPN Settings will work again, but without DHCP.
Hello, Doing exactly instructions from this tutorial I was not able to successfully create a VPN tunnel. Phase 2 error.
The CLI instructions shown in the tutorial: "set dhcp-ipsec enable HIGHLIGHT" returns me an error. The modified entry: "set dhcp ipsec-enable" is probably insufficient.
Is the DHCP on IPsec requires a Policy-based VPN?
In the documentation I see: "DHCP-IPsec - [...] Select this option if the FortiGate unit assigns VIP addresses to FortiClient dialup clients through a DHCP server or relay. This option is available only if the Remote Gateway in the Phase 1 configuration is set to Dialup User and it works only on policy-based VPNs."
Can I set DHCP on Dialup IPsec using only a Route-based VPN?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.