We are using a Gate running 7.4.7 as a RA IPSec VPN for our clients, and the FortiClient is version 7.4.3.1790. One of the servers has a GPO that enforces encryption between the various clients and a server, and this traffic is never placed in the tunnel. The firewall logs shows traffic to all other servers, but there is absolutely nothing to the one server for which encryption is enforced. Best way to describe this is IPSec encapsulated in IPSec. We checked the routes on the client systems, which look good. For testing, I installed and configured FC, logged into the VPN, and it connected to the server just fine. We cannot disable the encryption settings in the GPO.
This is a deal breaker. Does anyone have an idea of what I can try to make this work? Thank you.
Hello albaker1,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
I appreciate your time. I've continued to troubleshoot but can't get this to work.
can you share the details/config of the GPO in question ?
i would like to try it in a lab if i can
Is this adequate? Thanks for your time.
  
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.