?
Solved

Fortigate 50B Remote Client VPN Setup

Posted on 2010-09-09
6
Medium Priority
?
2,809 Views
Last Modified: 2012-05-10
I am trying to setup a remote user VPN, and no matter what i do, the clients can connect but they cannot the internal network when doing so. I created phase1/phase 2, and assigned a DHCP of 192.168.4.x to remote users, and my internal lan subnet is 192.168.5.x. They are authenticated but cannot reach anything in the 5.x subnet. I created a firewall policy to allow traffic from the WAN to the Internal LAN, and also from 192.168.4.x to 192.168.5.x, not sure what else to do at this point
0
Comment
Question by:Cobra25
6 Comments
 
LVL 5

Expert Comment

by:2Cs
ID: 33644858
No familiar with Fortigate but you need a network translation rule to say that 192.168.4.xxx are on the same network as 192.168.5.xxx.

What rule have you created? What ports, protocols, etc. does it allow?

Al
0
 
LVL 5

Expert Comment

by:2Cs
ID: 33644859
*network address translation (NAT)
0
 
LVL 4

Expert Comment

by:iworks-uworks
ID: 33648399
Are you trying to complete a site-to-site VPN? Or a user dial-up VPN?
Can you post a screen shot of your policy setup?
0
What Security Threats Are We Predicting for 2018?

Cryptocurrency, IoT botnets, MFA, and more! Hackers are already planning their next big attacks for 2018. Learn what you might face, and how to defend against it with our 2018 security predictions.

 
LVL 4

Author Comment

by:Cobra25
ID: 33648406
Its a user dial up VPN.

I got it working, by turning off the IP-Sec VPN.
0
 
LVL 4

Accepted Solution

by:
Whiterat earned 1500 total points
ID: 33651337
As far as I recall, Dialup IPSEC tunnels are created as a separate interface/zone.

i.e if the Phase1 of the dialup tunnel is called "DIALUP" then you must make a policy from the interface "DIALUP to LAN and vice versa.
0
 
LVL 4

Author Closing Comment

by:Cobra25
ID: 33666816
Sounds about right
0

Featured Post

Vote for the Most Valuable Expert

It’s time to recognize experts that go above and beyond with helpful solutions and engagement on site. Choose from the top experts in the Hall of Fame or on the right rail of your favorite topic page. Look for the blue “Nominate” button on their profile to vote.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question