Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Umesh
Contributor

unable to access Internet while connecting Forti client in laptop

Dear Folks,

 

While connecting Forticlinet vpn unable to access Internet in my laptop. I can access Internal network but the only Issue is unable to access web services like - https http.

 

I can ping 8.8.8.8 from laptop and also can traceroute.

 

Can anyone tell me what can be issue.

 

Thank you.

8 REPLIES 8
ozkanaltas
Contributor III

Hello @Umesh ,

 

I think the split tunnel feature is not used in your VPN configuration. Because of that, your all traffic goes through to Fortigate. If you don't have a firewall rule for this traffic you can't access the internet while connected to a VPN.

 

You can configure a firewall rule for this traffic or you can configure split tunnel for your user.

 

Also, you can review this document about split tunneling.

 

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/307303/ssl-vpn-split-tunnel-...

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Umesh
Contributor

Hi ozkanaltas,

 

Rule is configured for https, http, DNS, ping and traffic is going through that policy. I am able to ping 8.8.8.8 from my laptop when I connect forticlient vpn. only the issue is not able to access https services - like web services.

 

Next what can I do for troubleshooting.

 

Thank you in advaced. 

ozkanaltas

Hello @Umesh ,

 

Do you see any logs about your https traffic in your forward traffic logs? 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Umesh

Hello,

 

I am able to see traffic is passing through the policy for internet.

I can ping 8.8.8.8 but not google.com.

 

What can be issue. As far as I understand the issue can be DNS because until DNS resolve, how can I ping google.com

 

Note - able to ping 8.8.8.8 not google.com

 

hbac

@Umesh,

 

Obviously, it is a DNS issue. You need to check what is the IP address of the DNS server by running 'ipconfig /all' when connected to the VPN. What is the DNS settings on the FortiGate dialup tunnel?

 

Regards, 

hbac

Hi @Umesh,

 

Do you have split tunneling enabled? If not, you can run debug flow to see if traffic is being dropped: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...

 

Regards, 

Umesh

Hello,

 

I am using Remote access VPN as a Fortinet client. not SSL VPN.

 

Can you tell how can I enable spilt tunnel in Remote access vpn.

jera
Labels
Top Kudoed Authors