I have problem when i connecitng my forticlient to the ipsec vpn tunnel.
The issue is when i configure the forti client using ip address of fortigate then the vpn connected and can reach to the LAN.
But if i use dns name on the forticlient then the vpn is connected bt can't rach to anywhere.
Trying ping the dns name from the client and the ip is resolved.
Anyone know why?
i have you issue , you need to change you ipsec police and enable NAT this police
Apart from the fact that the DNS name of the FGT is resolvable as public IP, is it also resolvable as private IP on the local network?
Probably the issue is, when FCT connects to the FQDN (resolved to public IP) and get a new DNS server IP from IPsec, it is possible that the client resolves the FQDN to the private IP, and so FCT can't maintain the tunnel with the public FQDN anymore because it resolves now to the private IP. I'm not certain about this assumption but it looks for me this is what is happening.
| User | Count |
|---|---|
| 2910 | |
| 1451 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.