Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kapil
New Contributor

In Forticlient need to hide the publicp IP of the VPN setting

Hi,

   We are configured SSL VPN and IPSEC VPN. VPN users are installed by the latest Forticlient in their machines and connecting to the local network. But our clients can view the Public IP in the client configuration, So its not secure there is any possibility to hide the Public IP in clients.

 

 

Best Regards,

Kapil P

Executive - Technical Support

SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore

Best Regards, Kapil P Executive - Technical Support SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore
5 REPLIES 5
Toshi_Esumi
Esteemed Contributor III

Please elaborate what exactly the "Public IP" you're concerning about and where they can see. NAT outside IP or FortiGate's server IP? If any savvy enough user can figure out those IP with just opening up a command prompt, and a public ip is "public" anyway. So I don't know what's your concern is.

kapil

Whats the issue is, I have configured VPN client with my public IP for our clients, we have configured with split tunneling, then other internet traffic of the user will be forwarded to their network.So our public ip will not be  advertise.

We need to give some previlege at the user end, because there is possibilities to share our public IP and user name / passwd with other and there is risk.

 

 

Best Regards,

Kapil P

Executive - Technical Support

SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore

Best Regards, Kapil P Executive - Technical Support SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore
Toshi_Esumi
Esteemed Contributor III

I still don't quite get what you're trying to say. "Your public IP" is a part of public IP subnet your organization has been allocated by ARIN? And you provide internet service to your customers with "your public IP" at those VPN client locations?

Or you're using those public IPs to each VPN client tunnel IP, which you don't have to? "Your public IP" can be reached only through your network because that's where the prefix is advertised toward other Internet companies (peers) via BGP. They can't be routed to a third-party ISP's circuit wherever the VPN user is located.

Instead, if you're talking about the server (FortiGate) IP to connect VPN to, yes, of couse if a user bleaches server IP/URL w/ username/password, the person who got the info can get connected. No way to prevent it unless deploying two factor auth to add another layer.

Sudarsan_Babu

Dear Kapil,

 

what you try say need to block forticlient config setting (ipsec & ssl vpn configure from public ip which you company purchased from ISP) . If i understand correctly can you try this below link. 

 

http://help.fortinet.com/fclient/olh/5-6-2/FortiClient-5.6-Admin/1400_Settings/1600_Configuration%20...

 

Regards,

Sudarsan Babu P

Regards,

Sudarsan Babu P

Regards, Sudarsan Babu P
kapil
New Contributor

Hi Guys,

 

I understand that we need to configure two factor aunthentication to prevent unwanted logins.

thank you for the update

 

 

 

Best Regards,

Kapil P

Executive - Technical Support

SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore

Best Regards, Kapil P Executive - Technical Support SafeZone Secure Solutions Private Limited www.safezone.co.in / kapil@safezone.co.in Chennai | Coimbatore | Bangalore
Labels
Top Kudoed Authors