Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ed_ranz21
New Contributor

Subnet propagation in IPSec DialUp with split tunneling

Hi, we are facing a problem with the transition from SSL-VPN to IPSec DialUp for remote users.

The problem is that we want to maintain the functionality of the split tunnel from SSL-VPN, that means that all the subnets declared in the policies that affect the group that the user is part of, create an entry in the routing table of the client machine.

Just the subnets in the policies, and not the whole subnet(s) declared in the phase 2 of the IPSec tunnel.

 

Is this possibile ?

 

Also, some remote resources are reachable from the users only through the VPN client, because we declared the FQDN of the remote peer in the policies. To access those, should we disabling split tunneling at all ?

 

Currently we are working on Fortios 7.4.9, but we are planning to update to 7.6.2

 

Thanks

 

1 REPLY 1
funkylicious
SuperUser
SuperUser

hi,

only subnets specified in the split tunneling object in IPsec Phase1 will be installed on the computer connecting to the VPN, not the ones in the firewall rules.

as for FQDN, this will not be possible as per https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-split-tunnel-For-IPsec-VPN/ta-p/192... 

 

only subnets are possible to be selected in the split tunnel or /32 hosts, no ip ranges  - https://community.fortinet.com/t5/FortiGate/Technical-Tip-Enable-split-tunnel-For-IPsec-VPN/ta-p/192... 

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors