Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
c_n_s
New Contributor

VPN to different internal VLAN

Hello!

 

I have a Windows server, as a Windows RRAS VPN server, connected to the fortigate's "internal" interface. No one on the same network is able to connect the VPN, which is to be expected. Everyone outside the office can connect to the VPN with no problems.

 

The same firewall also has a guest VLAN, which has no access to the internal network, it only has one policy, to connect to the internet, and I'm trying to make the VPN work for computers on that VLAN. The computers are able to connect to the server, windows asks for credentials, and then drops.

 

I've tried policies, Virtual IP's, port forward, but can't get it to work.

 

Any help is much appreciated!

 

Thank you!

1 Solution
funkylicious
SuperUser
SuperUser

hi,

wouldn't it be simpler to just grant access to whatever LAN resources you want, rather than connecting to the VPN while already there ?

 

as for what you want to achieve, it could/should work directly using the private IP of the RAS server. just make the appropriate firewall policy for the traffic ( guest > internal ), opening the ports that your VPN would need.

"jack of all trades, master of none"

View solution in original post

"jack of all trades, master of none"
2 REPLIES 2
funkylicious
SuperUser
SuperUser

hi,

wouldn't it be simpler to just grant access to whatever LAN resources you want, rather than connecting to the VPN while already there ?

 

as for what you want to achieve, it could/should work directly using the private IP of the RAS server. just make the appropriate firewall policy for the traffic ( guest > internal ), opening the ports that your VPN would need.

"jack of all trades, master of none"
"jack of all trades, master of none"
c_n_s

Hello!

 

Turns out the connection wasn't going through because I had another third-party VPN connected. That VPN was set to continue running in the background with the application closed and I didn't notice that before.

 

In the end I didn't have to change the firewall configuration.

 

I'm marking your answer as a solution because of the idea to use the internal IP address of the server, which was what made me find out the other vpn was still connected.

 

Thank you very much for your help!

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors