Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DaltonPref
New Contributor

Ubuntu ipsec+telemetrty - wrong src IP

Hello,

I'm using strongswan to connect to a Fortigate IPSec VPN (that part of the setup is working properly).

Then I'm connecting - FortiClient Telemetry -(through the VPN) and trying to use Fortigate for setting up security policies.

 

The problem I'm having is that Ubuntu FortiClient Telemetry is reporting my WIFI interface IP, instead of my VPN IP, so the VPN traffic from my laptop is not tagged/matched with the policy setup via Telemetry.

Questions:

1) I'm assuming the IPSec traffic is tagged by matching the VPN source IP with the FortiClient Telemetry reported ip, is this correct?

2) Is there any configuration I can do in Ubuntu FortiClient Telemetry to bind it to the VPN tunnel interface?

3) Is this a "supported" configuration? (strongswan ipsec+ FortiClient Telemetry on Ubuntu)

 

Thank you!

 

OS: Ubuntu 22.04

Forticlient 7.0.6

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello Daltonpref,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

Hello,

 

We are still looking for an answer to your question.

We will come back to you as soon as we get it.

 

Regards,

Anthony-Fortinet Community Team.
DaltonPref

Hello Anthony,

Thank you for the update!

 

I will be looking forward to your reply.

Regards

Markus_M
Staff
Staff

Hi Dalton,

 

I think the Linux FortiClient does not speak IPSec which is why you use strongswan. The FortiClient will not be aware of the adapter IP as it does not understand this to be an important IP. Only its own adapter with its own MAC that it is aware of, can be used, if it used IPSec. SSLVPN would be your choice. So 2) SSLVPN, 3) No.

For 1)

I don't know the telemetry well, but would assume the IP is added by the client to the traffic it sends. If the telemetry depends on the source IP of the traffic, NAT would help of course.

 

 

Best regards,

 

Markus

Labels
Top Kudoed Authors