Troubleshooting Tip: Unable to reach local network after adding in the SSL VPN portal
| Description | This article explains the reasons for not detecting a local network after being advertised in the VPN configuration. |
| Scope | FortiGate. |
| Solution | The user belongs to both the full-access and admin portals in the SSL VPN configuration. Within the full-access local network, which is not advertised, user matching grants full access before matching the admin portal.
Non-working: user is part of both portals.
[188:root:bf8d81d]fsv_saml_auth_group:348 find a remote match group: 3dc6caa8-1435-4698-a448-9b417b5cc41b, portal: Admins, <------------ group: VPN_MFA_ERP.
Working: after removing the user from the Full-Access portal:
[188:root:bf8d06e]fsv_saml_auth_group:348 find a remote match group: 3dc6caa8-1435-4698-a448-9b417b5cc41b, portal: Admins, <---------- group: VPN_MFA_ERP.
Solution: Remove the user from the full-access portal to gain full access to the local network. |
