We are using Forticlient 7.2.1 on Windows 10 22H2 with EMS cloud and assigning IPSEC VPN profiles to our endpoints. These profiles have split-tunnelling configured based on the EMS application definitions i.e. MS teams. What we are finding is that on many clients split-tunnelling is not occurring but on others it is even though they are assigned the same profile. Upon investigation we see that on the systems that are working they have explicit routes for the cloud services added to the Windows client (as viewed via the route print command on windows) but the endpoints that are not working do not.
Q: How can I determine what is causing this? Is there a tool I can use client side to see why these routes are not propagating (dump the config or the like)?
Hello shocko,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello shocko,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards,
Hello shocko,
After a lot of research and after consulting with our engineers, your only option is to open a TAC ticket and work with the FortiGate team.
Do not hesitate to come back to us if you need more information.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.