Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mrmcphisto
New Contributor

VPN basics

Hi all,

which is the difference between vpn tunnels and users?

For example, on the same vpn device we have 10 users but 15 tunnels (so more tunnels vs users), why? What cause this difference?

We've limited 1 tunnel per user as policy

 

And more, why session numbers are higher vs tunnels?

Thanks

3 REPLIES 3
mrmcphisto
New Contributor

Hi,

no tips?

rwpatterson
Valued Contributor III

SSL tunnels are 1-1. IPSec tunnels could have 1 user with multiple tunnels. You didn't state what type you are referring to.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
ede_pfau

hi,

 

assuming you are talking about IPsec VPN dial-in tunnels...

1- you can have more tunnels open than users if some users connect to more than 1 network. In IPsec VPN you can see one tunnel per phase2 selector (you can, you don't have to, it's config dependent) in the 'IPsec VPN monitor'. Strictly spoken it's one tunnel, but displayed as one line per phase2.

 

2- one application can open dozens of sessions, i.e. browsing, to increase the download volumen and improve the user's experience. That is absolutely normal, some protocols (services) do, some don't.

 


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors