We have two public IPs associated with a single domain name, which we use as the remote gateway in FortiClient. Recently, we replaced one of the public IPs with a new one. Since then, FortiClient VPN has not been working as expected when using the domain name. However, it works when we manually configure both IPs as gateways. What could be the issue, and how can we fix it?
FortiGate
are you using 2 different interfaces/ips or a single interface with a secondary on it ?
We are using two different interfaces.
ISP1 connected in WAN1
ISP2 connected in Port1
hi,
do you have sdwan or ECMP enabled/configured on your firewall ?
or how does your routing table look like for the traffic ?
We are using the SDWAN in our firewall
does the dns/domain being resolved in the IPs of the interfaces in question ?
Yes, the DNS resolve the IP address
ok, then everything should be in order.
can you elaborate on what or how the issue manifests ?
When user try to connect forticlient VPN it is connected. After 2-3 seconds it gets disconnected
try https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enabling-the-preserve-session-route/ta-p/1... if not already been implemented, otherwise i would suggest starting a debug and test to get some logs of what is happening and maybe why the user gets disconnected.
User | Count |
---|---|
2276 | |
1236 | |
772 | |
452 | |
398 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.