Chapter 11 IPsec VPN for FortiOS 5.0 : FortiClient dialup-client configurations : FortiClient-to-FortiGate VPN configuration steps
  
FortiClient-to-FortiGate VPN configuration steps
Configuring dialup client capability for FortiClient dialup clients involves the following general configuration steps:
1. If you will be using VIP addresses to identify dialup clients, determine which VIP addresses to use. As a precaution, consider using VIP addresses that are not commonly used.
2. Configure the FortiGate unit to act as a dialup server. See “Configure the FortiGate unit”.
3. If the dialup clients will be configured to obtain VIP addresses through DHCP over IPsec, configure the FortiGate unit to act as a DHCP server or to relay DHCP requests to an external DHCP server.
4. Configure the dialup clients. See “Configure the FortiClient Endpoint Security application”.
 
When a FortiGate unit has been configured to accept connections from FortiClient dialup-clients, you can optionally arrange to have an IPsec VPN configuration downloaded to FortiClient dialup clients automatically. For more information, see “Configuring the FortiGate unit as a VPN policy server”.