Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DamianLozano
New Contributor

VPN for Windows Clients with local internet browsing

Hello, thanks for your help.

 

I have a previous post with the same subject but I think it is better to dont revive the old post.

I have Fortigate 60D with an old firmware: 5.2.0

Someone give me the following link, this worked for me but with FortiClient:

https://kb.fortinet.com/kb/viewContent.do?externalId=FD36253

I would like to know if there is another tutorial to create a VPN for Windows client instead of FortiClient, I didnt found anything like this on Internet

 

Thanks in advance.

Regards,

Damián

 

13 REPLIES 13
orani
Contributor II

I have never tried this but what about following the ipsec vpn for windows steps? Creating an IPsec VPN from network & internet settings of windows might work.

Orestis Nikolaidis

Network Engineer/IT Administrator

Orestis Nikolaidis Network Engineer/IT Administrator
DamianLozano

Orani, thanks for your response.

Every time I created an IPSec VPN in fortigate, the clients allways navigate trough the remote fortigate (with the proper filter rules).

I think I tried just enabling "Split tunnel" but it never worked

If someone has a tutorial would be nice.

I just noticed the following:

- I have no IPSec template without forticlient

- If I select "Custom VPN Tunnel (No Template)", after 2 seconds, the fortigate logout itself

 

The "Dialup - Android (Native L2TP/IPsec)" will also work for Windows clients? 

 

Thanks, regards,

Damián

sw2090
Honored Contributor

the FortiGate has to do Split Tunneling not the client.

Without split tunneling ALL traffic will navigate through the fortigate since the client (no matter if forticlient or other) will change your default route.

With split tunneling enabled and set to a group of networks on the fortigate the client will set a network route for every of those networks and leave the default route untouched.

So internet traffic will navigate the usual way and only traffic to those networks will navigate through the fortigate.

This is not a client isse.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
DamianLozano

Thanks SW2090,

 

I know that it depends on the fortigate, sorry if I didnt explain this

I just want to know how to configure the fortigate to accomplish this with a IPSec VPN

Which kind of VPN should I create? Should I use a template? Which template?

 

Thanks

Regards

Damián

sw2090
Honored Contributor

I cannot tell you. We use ipsec with forticlient but also some OSX Client on Mac. On our FGT it is just set up as standard ipsec tunnel with split tunneling enabled.

The profile might depend on the vpn client you use...

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
Honored Contributor

Alas I set it up as dial up tunnel with the wizzard most times but it has afterwards to be converted to a custom ipsec tunnel to be able to enable and configure split tunneling.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
DamianLozano

SW2090, thanks for your response.

 

Sorry, when I create a VPN the following options appears:

- Dialup - FortiClient (Windows, Mac OS, Android) - Site to Site - FortiGate - Dialup - iOS (Native) - Dialup - Android (Native L2TP/IPsec) - Dialup - Cisco Firewall - Site to Site - Cisco - Custom VPN Tunnel (No Template)    Which one should I use? The last option (Custom VPN Tunnel) is not working because when I select it and click "next", after about 3 seconds the fortigate automatically log out Do you know why? Should I use cli instead?  I think I would need a guide to create it trough cli.   Thanks in advance. Regards Damián
sw2090
Honored Contributor

I use Dialup - Forticlient as profile. 

You have to convert it to a custom vpn tunnel afterwards because you won't see split tunneling if you don't.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
DamianLozano

Thanks,

Converting the VPN to custom will allow me to connect from Windows client without FortiClient?

This is what I wanted from the begining

 

Regards,

Damián

Labels
Top Kudoed Authors