Skip to main content
athirat
Staff
Staff
March 30, 2022

Technical Tip: Unable to add the SSL-VPN pool subnet as local subnet in OCVPN with error 'Only internal subnets are allowed'

  • March 30, 2022
  • 0 replies
  • 625 views
Description

This article describes how to add SSL-VPN pool subnet into the OCVPN overlay.

Scope All FortiOS versions.
Solution

- This error is seen because FortiGate by default performs a route lookup for the local subnet being added in OCVPN.

 

- In the case of SSL-VPN pool, since no route for this subnet is available in the routing table, the error 'Only internal subnets are allowed' is displayed on GUI.

- The workaround is to add a dummy route as below on FortiGate for the SSL-VPN subnet which should resolve the issue in hand:

Create a static route such that:


subnet : ssl vpn pool
gateway: let this be 0.0.0.0
Interface: ssl.root.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!