FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
hbac
Staff
Staff
Article Id 311764
Description This article describes an issue when users connect to a dial-up IPsec tunnel from FortiClient, the internet connection drops during the IPsec negotiation. 
Scope FortiOS, FortiClient.
Solution

It is a default behavior as FortiClient blocks all outbound non-IKE traffic during the IPsec negotiation. This can be an issue if the user's computer is accessed remotely. 

 

To allow outbound non-IKE traffic during the negotiation, it is necessary to modify the XML file of the FortiClient.

If FortiClient is managed by EMS, an XML file can be configured on the EMS. For unmanaged/free FortiClient, follow the steps below:

  1. Backup the FortiClient configuration to a file as shown below. Remember the password because it will be necessary when restoring the configuration file later. 

 

backup.PNG

 

  1. Edit the backup configuration file in Notepad. In this example, a dialup IPsec VPN connection is configured named 'Dialup'. Change <implied_SPDO> value to 1 and <implied_SPDO_timeout> to 60

 

config.PNG

 

  1. Save the configuration file and restore it on FortiClient. If the restore button is greyed out, select the padlock on the top right to unlock. Restore using the same password from step 1. 

 

lock.PNG

 backup.PNG

 

Note:

For more information about <implied_SPDO> and <implied_SPDO_timeout> value, refer to IKE settings

Contributors