Our VPN clients (RAS on Server 2012 R2) seem to be registering their local IP from their home router in our DNS. e.g. 192.168.0.2<\/p>\n
Advertisement
I’m trying to get them to update DNS with an IP on our corporate subnet, so that I can deploy software etc via domain name (I can connect via the assigned IP via the RAS server, but DNS is not updating to reflect this assigned IP)<\/p>\n
Advertisement
We have a Fortigate firewall and was wondering if I could use a NAT rule on our incoming traffic to a dynamic pool? I have an IP range ready for this but unsure what dynamic pool ‘type’ I would use. The pool would be a range on our subnet.<\/p>\n
I’ve also read about possibly setting up a VDOM to achieve this, but having never done this before, just wondered if any of you had run into similar issues/if there’s an easier workaround.<\/p>\n
Thanks in advance<\/p>","upvoteCount":11,"answerCount":14,"datePublished":"2020-11-13T10:27:56.000Z","author":{"@type":"Person","name":"friendlywire","url":"https://community.spiceworks.com/u/friendlywire"},"acceptedAnswer":{"@type":"Answer","text":"
okay, so do they always work from home, or do they go back and forth between home and office?<\/p>\n
I found one solution was to have the ssl vpn adapter checked to register with DNS, then remove it for the local lan or wireless adapter.<\/p>\n
that got our remote uses to only register the IP they received via VPN, but if they were to come into the office we would have a problem.<\/p>","upvoteCount":1,"datePublished":"2020-11-13T12:16:52.000Z","url":"https://community.spiceworks.com/t/nat-vpn-clients-to-an-internal-ip/781818/6","author":{"@type":"Person","name":"jamestkirk","url":"https://community.spiceworks.com/u/jamestkirk"}},"suggestedAnswer":[{"@type":"Answer","text":"
Our VPN clients (RAS on Server 2012 R2) seem to be registering their local IP from their home router in our DNS. e.g. 192.168.0.2<\/p>\n
I’m trying to get them to update DNS with an IP on our corporate subnet, so that I can deploy software etc via domain name (I can connect via the assigned IP via the RAS server, but DNS is not updating to reflect this assigned IP)<\/p>\n
We have a Fortigate firewall and was wondering if I could use a NAT rule on our incoming traffic to a dynamic pool? I have an IP range ready for this but unsure what dynamic pool ‘type’ I would use. The pool would be a range on our subnet.<\/p>\n
I’ve also read about possibly setting up a VDOM to achieve this, but having never done this before, just wondered if any of you had run into similar issues/if there’s an easier workaround.<\/p>\n
Thanks in advance<\/p>","upvoteCount":11,"datePublished":"2020-11-13T10:27:56.000Z","url":"https://community.spiceworks.com/t/nat-vpn-clients-to-an-internal-ip/781818/1","author":{"@type":"Person","name":"friendlywire","url":"https://community.spiceworks.com/u/friendlywire"}},{"@type":"Answer","text":"
so you are not using forticlient for remote sessions? I ask because I have read that it requires the newer paid version of forticlient to register only the VPN address you give the remote user instead of the IP they get from their local router.<\/p>","upvoteCount":1,"datePublished":"2020-11-13T11:07:37.000Z","url":"https://community.spiceworks.com/t/nat-vpn-clients-to-an-internal-ip/781818/2","author":{"@type":"Person","name":"jamestkirk","url":"https://community.spiceworks.com/u/jamestkirk"}},{"@type":"Answer","text":"