Fortinet black logo

EMS Administration Guide

Source IP address anchoring for IPsec VPN

Source IP address anchoring for IPsec VPN

FortiOS requires endpoints' public IP addresses to achieve source IP address anchoring for IPsec VPN. FortiClient includes an enhancement to ensure that FortiClient provides a correct and reliable public IP address. You can then use the IP address in an on-Fabric detection rule in EMS.

This example configures an on-Fabric detection rule using the public IP address 208.91.115.30. The rule causes FortiClient to become on-Fabric or off-Fabric depending on if its public IP address is 208.91.115.30.

To configure an on-Fabric detection rule using a public IP address:
  1. Add an on-Fabric rule:
    1. In EMS, go to Endpoint Policy & Components > On-fabric Detection Rules.
    2. Click Add.
    3. Click Add Rule.
    4. From the Detection Type dropdown list, select Public IP.
    5. In the IP Address field, enter the desired IP address.
    6. Click Add Rule.
    7. Click Save.
  2. Go to Endpoint Profiles > Remote Access.
  3. Create two Remote Access profiles, one for off-Fabric endpoints and one for on-Fabric endpoints. The profile for on-Fabric endpoints is disabled, while the profile for off-Fabric endpoints is enabled.

  4. Go to Endpoint Policy & Components > Manage Policies.
  5. Click Add.
  6. Enable Profile (Off-Fabric).
  7. Configure the on- and off-Fabric VPN profiles as you configured.
  8. Configure other fields as desired, then click Save. Once FortiClient receives the configuration, since it is on-Fabric, the Remote Access tab is not visible in FortiClient. If the FortiClient IP address does not match the one defined in the on-Fabric detection rule, the endpoint is considered off-Fabric and the Remote Access tab appears in FortiClient.

Source IP address anchoring for IPsec VPN

FortiOS requires endpoints' public IP addresses to achieve source IP address anchoring for IPsec VPN. FortiClient includes an enhancement to ensure that FortiClient provides a correct and reliable public IP address. You can then use the IP address in an on-Fabric detection rule in EMS.

This example configures an on-Fabric detection rule using the public IP address 208.91.115.30. The rule causes FortiClient to become on-Fabric or off-Fabric depending on if its public IP address is 208.91.115.30.

To configure an on-Fabric detection rule using a public IP address:
  1. Add an on-Fabric rule:
    1. In EMS, go to Endpoint Policy & Components > On-fabric Detection Rules.
    2. Click Add.
    3. Click Add Rule.
    4. From the Detection Type dropdown list, select Public IP.
    5. In the IP Address field, enter the desired IP address.
    6. Click Add Rule.
    7. Click Save.
  2. Go to Endpoint Profiles > Remote Access.
  3. Create two Remote Access profiles, one for off-Fabric endpoints and one for on-Fabric endpoints. The profile for on-Fabric endpoints is disabled, while the profile for off-Fabric endpoints is enabled.

  4. Go to Endpoint Policy & Components > Manage Policies.
  5. Click Add.
  6. Enable Profile (Off-Fabric).
  7. Configure the on- and off-Fabric VPN profiles as you configured.
  8. Configure other fields as desired, then click Save. Once FortiClient receives the configuration, since it is on-Fabric, the Remote Access tab is not visible in FortiClient. If the FortiClient IP address does not match the one defined in the on-Fabric detection rule, the endpoint is considered off-Fabric and the Remote Access tab appears in FortiClient.