Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

Problems changing from SSL VPN to IPsec

Hi,

 

we changed to a FGT90G cluster and we have to change from SSL VPN to IPSec. We are running 7.4.7 and I think it will be the last image with SSL activated.

 

We only used SSL VPN since it seemed easier to configure with different Groups, etc. Now trying to do the same with IPSec we have several problems.

 

Our IPsec configuration:

>In the IPSec Client Address range we used another range than SSL VPN (X.X.X.50-100 and IPSec X.X.X.150-X.X.X.200.

>We enable Enable IPv4 Split Tunnel and define in Accessible Networks ALL since we want to have access to the LAN and also the MPLS networks

>In XAUTH  User Group we have INHERIT FROM POLICY to use the same user groups we had before with SSL VPN

 

Now our problems:

> With the Forticlient 7.2 we cant connect, the client shows connecting but nothing happens. Also in the FG I dont see any information about the IPSec access. With older versions, I tried a 6.4 the connection works.

 

> Since SPLIT Tunnel is activated I thought that we can browse localy but it is not working, users with IPSec connection cant navigate localy, I cant ping 8.8.8.8

 

> Also I have routing problems, for example I have access to a MPLS network but to the local LAN I dont. Since we copied all SSL VPN policies just changing from SSL VPN_range to IPSec_range I dont understand where is the problem. We tried with some policy routing, but SSL VPN works fine, I have access to all networks and in IPsec I dont. Is it something with the ALL network in my configuration?

 

Thanks!

 

1 Solution
RolandBaumgaertner72
Contributor III

Hey,

 

It seems to work now. I change from ALL in accesible networks to a group I created where we need access to and it works. 

 

Also it works with newest FC version 7.4 but I dont know what changed from yesterday to today that 6.4 was working yesterday and 7.4 not.

 

Seems like a solution for me.

 

Thanks1

View solution in original post

1 REPLY 1
RolandBaumgaertner72
Contributor III

Hey,

 

It seems to work now. I change from ALL in accesible networks to a group I created where we need access to and it works. 

 

Also it works with newest FC version 7.4 but I dont know what changed from yesterday to today that 6.4 was working yesterday and 7.4 not.

 

Seems like a solution for me.

 

Thanks1

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors