Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ejk2015
New Contributor

How do you allow local (LAN) access when connected to SSL VPN?

We switched from Cisco to Fortigate 240D and everything is working well except when my users connect to SSL VPN into a remote network behind the Fortigate FW, they lose access to their local network resources such as printer and server access.  In the past, we configured the Cisco AnyConnect to allow local (LAN) access when connected to VPN, but I don't see this option in FortiClient. 

 

What do I need to do to get this working?  Do I need to enable split tunneling and a static route? 

 

Thanks

 

Eddie

5 REPLIES 5
ejk2015
New Contributor

I was able to enable split tunneling and everything works now.

laf
New Contributor II

Can anyone please detail the workaround here?

I have a full-tunnel ON but I need an exception for LOCAL LAN segment? 

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
bashrael
New Contributor

Hi,

I am not sure if this will be working for you but I had a similar problem with an ipsec tunnel.

check this post: https://forum.fortinet.com/tm.aspx?m=143896&tree=true

 

most important:

backup your config in forticlient and edit the backup file add following: In the <ipsecvpn> section after </options> add these xml tags so it would with the xml file structure:  <connections>  <connection>  <ike_settings>  <enable_local_lan>1</enable_local_lan>  </ike_settings>  </connection>  </connections>  </ipsecvpn>    save and restore this file in your forticlient.

 

But off course you will have to adjust it for your sslvpn tunnel..

 

grt

bshr

 

MikePruett
Valued Contributor

Split tunneling is the only resolution to this issue. Well, that and ensuring that both sides have separate IP space.

Mike Pruett Fortinet GURU | Fortinet Training Videos
bashrael

Is that because it is a ssl tunnel?

 

I have an ipsec tunnel without split tunneling enabled and after setting "<enable_local_lan>1</enable_local_lan>" I am able to access my local lan.  All the other traffic is going over the tunnel.

Labels
Top Kudoed Authors