Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
altanet
New Contributor

Multiple FortiClientVPN IPsec Connections from same ISP/IP address???

I can' t find any mention (in KB or forums) of how to handle duplicate source IPs from IPsec VPN clients. Multiple users from hotel or other common ISP media are knocking each other off as the subsequent user (from same ISP/IP) creates a tunnel. FortiClientVPN s/w is 4.2.3/build0271 against FG200B @ v4.0MR3 (build0441) Please let me know if this is a known issue and if there is a solution. Thank you
8 REPLIES 8
altanet
New Contributor

Could someone please lend some feedback ? The Cisco VPN client can do this all day long (mult sessions/same IP). Is this something I should know and is there a configuration to resolve ? Thank you
Carl_Wallmark
Valued Contributor

Hi, In CLI, you will find this on the Phase2-interface: route-overlap {overlap_option} Specify how FortiGate unit handles multiple dialup users with the same IP source address. Set overlap_option to one of the following: • allow — allow overlapping routes • use-new — delete the old route and add the new route • use-old — use the old route and do not add the new route Default is " use-new" , you should change this to " allow"

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
altanet
New Contributor

Many thanks Selective. I' ll hit the CLI manual harder in the future. Again, Thank you
darrell
New Contributor

Are you sure about that one? I think the easier fix is to use main mode instead of aggressive mode isn' t it?
Carl_Wallmark
Valued Contributor

Could be, i never had this problem. This is what the CLI manual says.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
ede_pfau
SuperUser
SuperUser

No Main mode for dial-in clients as their host address is not known in advance. What the phase 2 setting will do is create a route to a subnet instead of a single source address (x.y.z.n/32) to route the tunnel traffic back. Multiple clients are then separated by the tunnel ID (SPI). Never had to deal with such a situation but it could occur anytime if more than one road warrior stays at the same hotel. Please let us know if it works.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
altanet
New Contributor

Thanks all, Changing the route-overlap to ' allow' worked like a champ for Tunnel-mode/Agressive configuration for multiple FortiClient VPN sessions with the same source address. Also applied the same parameter to an Interface-mode/Main Mode configuration for iPhone VPN, but haven' t tested duplication yet - I am the only/first user. Thanks again
Carl_Wallmark
Valued Contributor

Weehoo !!

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors