So the new VPN tunnel in interface mode connects, that' s good.
Try to keep it simple - don' t use DHCP over IPsec now. Give your client a static IP (or just the one it has, it doesn' t matter).
For the tunnel, on the FGT you need:
- the VPN phase1 and phase2 definitions
the QM selectors should not be ' 0.0.0.0' , fill in the local subnet and the remote (client) subnet
-- that' s why you need 2 phase2 for 2 subnets --
- a policy tunnel->internal, or tunnel->DMZ; ANY service; ACCEPT action (!)
A temporary route (/32) to the dial-in client will be created automatically.
On the Forticlient:
- the VPN parameters
- one subnet (LAN) entered on the first page
- ' Advanced' , add the DMZ subnet as well
The ' Dial-in VPN' example in the FortiOS Handbook will work as printed. This is not really magic.
Ede Kernel panic: Aiee, killing interrupt handler!