Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

subnet mask problem with ssl tunnel VPN

The tunnel VPN almost worked the way I wanted it to. It picked up one of the reserved IP addresses, but the subnet mask was 255.255.255.255 instead of 255.255.255.0. I set up the destination network with a subnet mask of 255.255.255.0 so I don' t know why it used the other subnet mask. Does it matter what interface I set the network to.? Right now I have it set to ANY.
29 REPLIES 29
Not applicable

When I enter the command IPCONFIG /ALL It says DHCP enabled is NO and there is no default gateway. The DNS and WINS servers all show up though.
rwpatterson
Valued Contributor III

Make sure that in the policy, the source address is set to ' all' . Don' t ask why. Specifying a source stopped working with MR4. You' re guaranteed that only the correct users will hit the servers in the destination field because they are the only ones authenticated in this policy.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

I should add that I am using a dial-up connection instead of broadband. I found this article: http://kc.forticare.com/default.asp?id=1722&Lang=1&SID= ...but it doesn' t work. Every time I activate the tunnel, the box is unchecked again.
Not applicable

Could it be a server configuration that is causing the problem?
Not applicable

OK, I' ve ALMOST got it working now. I turned off split tunneling and now I get a default gateway, but the gateway address is exactly the same as the IP address that was assigned to the laptop. Anyone know how to fix this? DHCP enabled still says no. Do I need to turn on the DHCP relay agent on the WAN interface(Regular since this is not a IPSEC VPN)?
Not applicable

I tried adding a DHCP relay agent on the WAN interface and that didn' t work. I deleted that and then added a DHCP server on the WAN interface and that didn' t work either. I still don' t get the correct gateway IP. The gateway IP that gets assigned is the same IP as the remote computer. When I configured a DHCP server on the WAN interface, I had to enter in the default gateway. Why wouldn' t this get picked up by the remote computer?
rwpatterson
Valued Contributor III

Let' s start from the beginning. Forticlient version, FGT version, PC OS version.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

FortiClient: 3.0.142 FortiGate: Fortigate-100A 3.00-b0572(MR5 Patch 4) OS: Windows XP Professional SP2
rwpatterson
Valued Contributor III

I would seriously start with an upgrade of the FortiClient. The key should still work on the latest build (MR5 build 3.0.473, P3). Download it from the Fortinet support site.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

I thought the FortiClient was only for IPsec. I need it for SSL as well?
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors