Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
movi28
New Contributor

SSL VPN Same subnet

Hello everybody, This is my firt post on this forum. I have a problem by a customer with a SSL VPN Tunnel Mode. I have a fortigate 60c and i have: 1 subnet 192.168.1.x for the office and: 1 subnet 192.168.1.x for a extern user. And that' s doesnt work naturly. Can I have a solution in this case ? I can' t change the subnet office and may be other SSL VPN have the subnet 192.168.1.x Thanks Regards Vinz
5 REPLIES 5
rwpatterson
Valued Contributor III

Welcome to the forums. I' m not sure about web mode SSL VPN, since I really don' t use it, but with tunnel mode, this isn' t an issue. When you create the portal for tunnel mode, you select a subnet (or IP range) that the SSL VPN users will be presented as to the LAN (or DMZ, etc.) This IP range is what the SSL VPN users will all use on the way in, regardless of what subnets they really have in their individual LANs. Make it unique, and you should be good to go.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
movi28
New Contributor

Thanks for your post. But the problem is: The server has a ip like 192.168.1.20 and when the user ping or connect to this ip he ping the locally adress and not the adress in office. What can I do ?
astibal
New Contributor

I am not sure if it would help you, but in the CLI, there is portal-specific option
exclusive-routing {enable | disable} Enable to force traffic between the client and the client’s local network to pass through the SSL VPN tunnel. This can enhance security. By default, an SSL VPN with split-tunneling disabled does not affect traffic between the client and the client’s local network, even though all other traffic is routed through the SSL VPN tunnel. exclusive-routing is available only when splittunneling is disabled.
This will have side effects, like other people on the very same portal will not be able access their local LANs.
-- Evolve or die!
-- Evolve or die!
movi28
New Contributor

Hello, Ok I have tried to conect to the SSL VPN with the Fortigate Client not just the SSL CLient and thats work :) !! But all the traffic go trough the ssl vpn include internet. It' s possible to separate that ? regards, Vince
astibal
New Contributor

Glad to see it working. For my curiosity: did you try to use exclusive-routing as suggested by me recently? A.
-- Evolve or die!
-- Evolve or die!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors