Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tsug
New Contributor

"Adding Route in Windows After Connection via Forticlient to Portal with Enabled Split"

We are facing an issue when connecting to Forticlient on specific machines, whether they are outside the domain or within the domain.

The SSL tunnel has split tunneling enabled for 3 networks:

  • 10.1.0.0/16
  • 10.10.0.0/16
  • 10.20.0.0/16

After connecting to the client, the addition of the 3 routes is correctly directed to the SSL VPN gateway. However, after a few seconds, another route is added for the 10.1.0.0/24 network, directing it to the client's home router gateway.

As a result, traffic is being sent to the local client's router instead of going through the firewall.

I conducted some tests and verified that the VPN configuration has the IP 10.1.0.2 as the DNS, and in the portal, it's set as DNS 0.0.0.0/0.

When I change the DNS Set in the portal specifically to a public DNS, the 3 default routes are inserted in the Windows route print, and I don't encounter route addition problems later on.

Upon changing the set dns-server1 from 8.8.8.8 to 10.1.0.2 in the portal, the issue of adding a route to the local client's router gateway resurfaces.

Regards,
Tsug.
Regards,Tsug.
4 REPLIES 4
vsahu
Staff
Staff

Hello Tsug,

 

Can you share the route print and ipconfig /all details? from both scenarios, also the DNS configuration where you're changing it can you share the snapshot of the same?

Regards,
Vishal
Tsug
New Contributor

-

Regards,
Tsug.
Regards,Tsug.
vsahu

Tsug,


I believe the output has been removed, Is it possible for you to attach the output again?  route print and ipconfig /all with and without VPN with DNS 10.1.0.2 and without DNS 10.1.0.2

Regards,
Vishal
djp
New Contributor

Looks like a Dell issue, fix here:


"To address this issue, uninstall Dell Optimizer or at least disable ExpressConnect:"

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Extra-route-in-Windows-routing-table-when/...

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors