Troubleshooting Tip: Unable to reach remote subnets when connected to IPsec VPN FortiClient Remote Access
| Description | This article describes an issue when a user is unable to reach remote subnet when connected to IPsec VPN FortiClient Remote Access due to redundant Group configuration. |
| Scope | FortiGate. |
| Solution | There are two ways to configure a user group in a Remote Access Dial-up connection.
IPsec Phase 1 Configuration:
Firewall Policy Configuration:
IPsec Phase 1 Configuration:
Firewall Policy Configuration:
A problem will arise when the user group is defined on both the firewall policy and the IPsec phase 1 configuration. The IPsec traffic will not match the correct policy and will hit implicit deny.
To diagnose the issue, the administrator needs to run a debug.
diagnose debug flow filter saddr X.X.X.X <----- Specify the VPN IP assigned to the user.
The debug flow output will be like this:
To disable the debug:
diagnose debug reset
To fix the issue, make sure to follow the guidelines above and configure the user group on either phase1 configuration or the firewall policy only.
Related article: Troubleshooting tip: Error 'No route exists from source address' with policy matching |





