Troubleshooting Tip: SSL VPN through a perimeter FortiGate is not working
| Description | This article describes a structured approach to configuring SSL VPN in a dual-FortiGate setup. |
| Scope | FortiGate. |
| Solution | In a network setup where an External FortiGate manages VPN access and an Internal FortiGate secures internal resources, remote users can securely connect to the internal LAN through SSL VPN on the External FortiGate.
Network Topology:
:desktop_computer: Remote Users (SSL_Client) -> :globe_with_meridians: Internet -> :locked: External FortiGate (SSL VPN) -> :office_building: Internal FortiGate -> :open_file_folder: Internal LAN.
Firewall policy on the perimeter FortiGate: A policy needs to allow expected traffic through the configured VIP to the internal firewall.
Testing SSL VPN Connection via FortiClient Through the Perimeter FortiGate to the Internal LAN:
Following these steps will ensure a functional SSL VPN connection behind the Perimeter FortiGate.
Related documents: |
