Hi,
When connecting to a FortiGate via IPsec VPN that is configured with email OTP, it is expected behavior that the local PC loses internet connectivity until the OTP is provided and the VPN completes the authentication process. This security feature is intended to ensure that while the VPN session is being established and before user authentication is fully completed, only the essential VPN traffic is permitted and all other communication is blocked on the client device.
Now i am looking for a solution to override this to allow Internet Access for OTP Retrieval so that at least it can be taken from email.
Thanks
Rohit k
Hello @rohitchoudhary1978
How are the split tunneling configurations ?
regards,
Sheikh
Hi,
The issue is resolved now.
Solution : I have download the backup of forticlient config and edit the file and made the changes as :
The <implied_SPDO> tag controls if all traffic is blocked before full authentication.
- The <implied_SPDO_timeout> tag can be set (e.g., 60 seconds) to allow a grace period during which the PC can maintain some network access—for example, to receive the OTP via email—before the lockdown is enforced.
- Increasing the timeout gives users a window to fetch their OTP before full lockdown, if necessary.
<implied_SPDO>1</implied_SPDO>
<implied_SPDO_timeout>200</implied_SPDO_timeout>
Thanks
Rohit k
Hello @rohitchoudhary1978
Thanks for sharing these details, it will be helpful for someone :)
regards,
Sheikh
User | Count |
---|---|
2609 | |
1390 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.