Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JustinDuffy
New Contributor

L2TP in 5.0

This is more a so you know for anyone trying to setup a L2TP connection on their fortigate and following the cookbooks instructions. The fortigate i' m doing this on is running version 5.0.7 so bear in mind how often things don' t follow the same instructions for each revision. That being said there are two things you will need to note when setting this up. Firstly there is a checkbox that will need to be unselected that they don' t make mention to in the cookbook, but they do picture it. This is under the Phase2 configuration under advanced and then under P2 Proposal. Uncheck the Enable perfect forward secrecy (PFS). This was throwing up connection errors in the event logs for the Phase2 and prohibiting me from establishing the connection. The second is one that needs to be updated in their documentation, there is a section for " Creating a security policy for access to the internal network and the internet" This only allows you to still have internet access and will not give you access to the internal network. You will also need to add a normal policy going from you outside interface using the vpn_pool address range going to your internal interface and going to the internal network. After putting both of those in you should be able to establish your connection and be able to access your internal resources.
1 REPLY 1
TuncayBAS
Contributor II

I thank you so much for your explanation. You' ve touched on a beautiful spot.
Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors