Created on ‎05-07-2009 02:36 PM
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Created on ‎05-27-2009 07:53 AM
Created on ‎05-27-2009 09:03 AM
Created on ‎05-27-2009 09:32 AM
Created on ‎05-27-2009 10:00 AM
What is confusing about the instructions is they refer to port 1 and port 2 on the diagrams.which instructions do you refer to? The local interface must be the interface to which the forticlient connects. Since the FortiClients are coming from the internet it must be one of your external interfaces (wan1 or wan2, depending on your configuration). If it says " already in use" check if there already is a Dialup VPN Tunnel configured for that interface. The firewall policy has to be from internal to external, where the source address is the network you want the dialup users to be able to access. The destination address would be the address the forticlient comes from. Since this address may change you might use any here.
In advanced I have DHCP-IPSEC enabled.Have you also configured the DHCP Server on your FortiGate? If not, go to System -> DHCP and create a new DHCP Relay for the interface you have specified in phase1. The type should be IPSec and the DHCP Server IP is of course the IP of your internal DHCP Server.
With the connecting client we have tried using Automatic and putting in the external IP of the Fortigate unit. We also tried manual with specifying the IP and preshared key.Up to now, I have always used manuel configuration. Just enter the IP of your fortigate and the preshard key. In the advanced configuration acquire an IP via DHCP over IPSec. If nescessary configure the localID of the forticlient and you should be done.
Created on ‎05-27-2009 10:26 AM
Created on ‎05-27-2009 10:43 AM
My policy that I have set up is under the Wan1-->Internal section. Are you telling me I need to move this under the Internal --> Wan1 section? That doesn' t make logical sense since the Fortinet client is coming in from Wan1 and wants access to the internal network.Excactly, the policy hast to be from internal to wan1. You can read through the configuration of the fortigate in the admin guide (page 37).
User | Count |
---|---|
2624 | |
1393 | |
804 | |
670 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.