Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

only one VPN client can establish connection at one time

We are currently using the Kerio Firewall 6.x to connect to the remote site using the Fortigate 100A. However, only one VPN client (forticlient v1.2.04) can connect to the VPN gateway at one time. The other workstation will fail to established the VPN connection. We set the outbound rule as follows for the VPN connection: Sources Destination Services allow Translation ------------- --------------- ------------------------ ----------------- internal IPs VPN gateway UDP 500, UDP 4500 NAT to WAN IP In the Fortigate 100A VPN gateway, we set the encryption rule with dial_up VPN gateway and place the rule at the top of the firewall policies. Thx
17 REPLIES 17
UkWizard
New Contributor

Or you could try agressive mode mode and use peerid with multiple dialup vpn rules (one for each peerid). Never tried this personally though, idea above is better. Also remember that every site would need its own individual IP subnet, otherwise it gets really messy and needs to be a site-to-site confg.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

hello, nearly the same problem here. forti100 with static IP, about 30 forti50A' s with dynamic IP' s. on the forti100 the first dialup-tunnel works fine. all others are getting a connection for about 1-30 seconds, then the connection is lost. log: " delete IPSEC..." misterious: it works fine for about 8 month. last softwareupdate 2 month ago. problem since yesterday...
Not applicable

hello, found the problem for my forti100... solved.
Not applicable

Hi Mr. Andy Neutatz, I am FG reseller in Malaysia. Myself also encountered this problem as yours before in my customer site and unable to resolve it. If is great to learn that you could overcome this problem eventually. Would you mind to share with me how you can resolove this problem? Thanks in advance. CK Chew Malaysia
Not applicable

Can you provide more information? As not all problems are the same...
Not applicable

Hi all, i am the original sender of this message. I have solved this problem by disabling the IPSEC traffic of my current firewall. Now i have have more than one VPN client connect to the remote site. Regards.
Not applicable

Hi Sir, Sorry I don' t get your message right. You are saying to disable the IPSEC traffic in the firewall, but how to do this? Is it disable the IKE service in the firewall policy (Internal to External, Encryption policy)? Thanks in advance. Chew
Not applicable

yes, not all firewall are the same. here i attached the pciture for my firewall setting that disable the IPSEC passthrough. After I unclick this option (IPSEC passthrough), the VPN clients work fine.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors