Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dosforever
New Contributor

How to access VPN client host from inside firerwall

first all, I'm not good at English, I don't know if I expressed exactly.

Firewall:Fortigate-200A, Firmware Version:3.00

The remote user can access to the HQ LAN inside firewall by PPTP dial up or Forticlient IPSec client. The remote host has the IP address segment same with the LAN host inside the firewall.

but I have a question. when VPN tunnel is built, how can I initiate access to the remote host?

I can not ping through the remote host, can not access remote host by Windows remote desktop, etc. Just like the remote host are not in the LAN.

1 REPLY 1
ede_pfau
SuperUser
SuperUser

hi,

 

and welcome to the forums.

 

Well, it is not in the LAN. So the FGT has to do routing to direct traffic to the client.

 

This is a technical peculiarity of dial-in VPNs. If you establish a client tunnel and look at the Routing Monitor you will see that the FGT has inserted a route between the FGT and the client automatically. But, both addresses are restricted to this one address by the '/32' netmask. So, traffic directly from the FGT can reach the client, and vice versa, but a host on the LAN cannot.

You cannot 'override' this automatic route as it already has the highest priority and lowest distance.

 

The same question pops up here in the forums regularily, and the answer is always the same: a client connection is not a site-to-site connection.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors