Hi,
We are configured SSL VPN and IPSEC VPN. VPN users are installed by the latest Forticlient in their machines and connecting to the local network. But our clients can view the Public IP in the client configuration, So its not secure there is any possibility to hide the Public IP in clients.
Best Regards,
Kapil P
Executive - Technical Support
SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore
Please elaborate what exactly the "Public IP" you're concerning about and where they can see. NAT outside IP or FortiGate's server IP? If any savvy enough user can figure out those IP with just opening up a command prompt, and a public ip is "public" anyway. So I don't know what's your concern is.
Whats the issue is, I have configured VPN client with my public IP for our clients, we have configured with split tunneling, then other internet traffic of the user will be forwarded to their network.So our public ip will not be advertise.
We need to give some previlege at the user end, because there is possibilities to share our public IP and user name / passwd with other and there is risk.
Best Regards,
Kapil P
Executive - Technical Support
SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore
I still don't quite get what you're trying to say. "Your public IP" is a part of public IP subnet your organization has been allocated by ARIN? And you provide internet service to your customers with "your public IP" at those VPN client locations?
Or you're using those public IPs to each VPN client tunnel IP, which you don't have to? "Your public IP" can be reached only through your network because that's where the prefix is advertised toward other Internet companies (peers) via BGP. They can't be routed to a third-party ISP's circuit wherever the VPN user is located.
Instead, if you're talking about the server (FortiGate) IP to connect VPN to, yes, of couse if a user bleaches server IP/URL w/ username/password, the person who got the info can get connected. No way to prevent it unless deploying two factor auth to add another layer.
Dear Kapil,
what you try say need to block forticlient config setting (ipsec & ssl vpn configure from public ip which you company purchased from ISP) . If i understand correctly can you try this below link.
Regards,
Sudarsan Babu P
Regards,
Sudarsan Babu P
Hi Guys,
I understand that we need to configure two factor aunthentication to prevent unwanted logins.
thank you for the update
Best Regards,
Kapil P
Executive - Technical Support
SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.