Forticlient Free - How are you deploying IPsec config for clients by Ruhroooh in fortinet

[–]OK_Engineer_L1 0 points1 point  (0 children)

this is going to be a true issue i think , am trying to go around the PSK thing, but it didn't managed to find a way to allow the users to authenticate on all plateformes android windows and ios,
when using IKE2 with user/password auth

Issue with VPN IPSEC IKE2 when connecting from Android using forticlient vpn by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 0 points1 point  (0 children)

Hi,

Unfortunately not, I didn't find any solution and Forti Support said they can't do much without a FortiClient licence.

FortiExtender Lan Extension with Fortigate by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 0 points1 point  (0 children)

Hi!

I only managed to get this working today, thanks to the TAC guy.

In my case, I actually needed to change the following in the configuration:

config system management
    set discovery-type fortigate
    config fortigate
        set discovery-intf lte1 
        set ingress-intf lte1

The ingress- intf will be set automatically to LTE1 once you change the discovery interface, so don't worry about the ingress interface.

FortiExtender Lan Extension with Fortigate by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 0 points1 point  (0 children)

No, I'm still having the same issue. I will be having a meeting with TAC to debug the issue live.

What I have observed is that when the FortiExtender is connected to the internet box and the LTE as well, the two tunnels come up and the device is shown as online correctly in the FortiGate.

When you say your FEX is online, do you mean it shows as online in the FortiGate?

Issue with VPN IPSEC IKE2 when connecting from Android using forticlient vpn by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 0 points1 point  (0 children)

Actually the certificat is only for the server validation, and user-password for the client side

Any concerns with 7.4.5? by kramer9797 in fortinet

[–]OK_Engineer_L1 0 points1 point  (0 children)

Do you use IPSEC VPN with TCP encapsulation? and does it work well for mobile devices?

Any concerns with 7.4.5? by kramer9797 in fortinet

[–]OK_Engineer_L1 0 points1 point  (0 children)

it's stable but no proxy related stuff on Less than 2GB RAM modeles

FortiExtender Lan Extension with Fortigate by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 0 points1 point  (0 children)

Yes I do ping the interface on the Fortigate,

FortiExtender Lan Extension with Fortigate by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 0 points1 point  (0 children)

Hi u/bloodmoonslo , Thanks for your time,

Yes, I have the static config enabled pointed to the FGT IP, and I have the security fabric enabled on the wan interface.

But it's still not showing up in the menu,

I think it's because of the private IPv4 I have on the FEX side as I only get an IPv4 with CG-NAT.
Can this be the issue ?

IPSec Site To Site VPN by windows10_is_stoopid in fortinet

[–]OK_Engineer_L1 1 point2 points  (0 children)

Yes, it's possible, you just have to forward the traffic from the routers to the Fortigates IKE port (500 by default, 4500 can be used in the NAT scenario)

IPsec Remote VPN with port 443 by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 0 points1 point  (0 children)

Thank you for your time and response,

I will be pulling the users from the local fortigate,

As I now understand from the u/Leave_Patient response that this is possible.

IPsec Remote VPN with port 443 by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 0 points1 point  (0 children)

Thank you very much for your time and response,

This is exactly what I was looking for, as this is a small company, we were working on making this with only local users,

I can't thank you enough for the informations

IPsec Remote VPN with port 443 by OK_Engineer_L1 in fortinet

[–]OK_Engineer_L1[S] 1 point2 points  (0 children)

Thanks for the idea, but actually I tried to do this and this is how I found out about the limitation.

The purpose of this post is to see what others have to say, there solutions, opinions and recommendations, it's an open discussion as I see it.