Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

how to disable split tunneling

how do i disable split tunneling after establishing IPSEC vpn between forticlient and fortigate. I want my dial in clients not to use internet after establishing ipsec session and only use smtp
5 REPLIES 5
ede_pfau
SuperUser
SuperUser

This is configured on the FortiClient. If the destination subnet behind the tunnel is ' 0.0.0.0/0' all traffic is going into the tunnel. If the tunnel only allows SMTP then the clients will not be able to use the internet for anything else.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
bmann
New Contributor

0.0.0.0/0 do this job. But I have found, taht on my WinXP SP3 this route is not propagated to the routing table. I had to add it manualy. Does anyone know why?
rmnetops
New Contributor

We are seeing the same issue. Anyone know a fix for this? bump
FortiRack_Eric
New Contributor III

first add your normal remote subnet (like 192.168.100.0/24) then add a second remote subnet 0.0.0.0/0 Cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
rmnetops
New Contributor

Ok I figured out the problem. I got it working using 0.0.0.0/0.0.0.0 as the only remote network configured on the Forticlient. For some reason, if you are using a FortiGate DHCP server service for the IPSEC client connections, and you don' t have a Default Gateway configured in the DHCP configuration, the clients will have a blank default gateway while connected. If you configure static IP address settings for the IPSEC connection at the Forticlient, it will automatically assign a default gateway for you. To get the DHCP setting to work on the Forticlient, I had to configure a default gateway in the DHCP server service settings on the FortiGate. I used the IP address of our internal Fortigate interface.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors