Skip to main content
papapuff
New Member
June 12, 2020
Solved

can't login web portal vpn ssl

  • June 12, 2020
  • 7 replies
  • 16788 views

Hi there,

I use FG60D, and wanna use VPN web portal.

what I've done:

- create web tunnel

- set AV check

- create user and group, then add to portal mapping on menu vpn ssl setting

 

I can reach web portal over web browser, directly, using assigned port.

but I can't login, permission denied.

am I missed something?

 

unlucky for me, tried to search over forum and fortigate help, but can't find about complete guidance.

 

also, Can I disable this feature, in the future? I mean outside can't reach web portal.

 

please help. thank you.

    Best answer by shehab

    If you are reaching the web page in the browser, dose not mean you configured the portal / users correctly.

     

    You are getting permission denied , because the user / group are not configured correctly.

     

    I am not sure what you want to achieve but , you have to create a web-portal and assign users to it, in the web-portal you can enable either or both tunnel mode and web mode.

     

    also, make sure you define the users inside the groups with out duplication , and at the end of the list you will see the default group assignment if the user is not defined in any group.

     

    Regards,

    Mahmood

    7 replies

    cwb2205
    New Member
    June 12, 2020

    Are you adding the user directly to the SSLVPN Auth/ portal mapping or adding them to a group and adding the group to the mapping?

    did you add a portal to the users auth /portal mapping?

    Patel
    New Member
    June 12, 2020

    You will need a policy from the sslvpn.root(if using root vdom) interface to internal network or the other way around in order to make it work. Make sure you have at least one policy referring the SSL-VPN interface.

     

    Regards,

    Patel

    shehab
    shehabAnswer
    New Member
    June 12, 2020

    If you are reaching the web page in the browser, dose not mean you configured the portal / users correctly.

     

    You are getting permission denied , because the user / group are not configured correctly.

     

    I am not sure what you want to achieve but , you have to create a web-portal and assign users to it, in the web-portal you can enable either or both tunnel mode and web mode.

     

    also, make sure you define the users inside the groups with out duplication , and at the end of the list you will see the default group assignment if the user is not defined in any group.

     

    Regards,

    Mahmood

    tcendros
    New Member
    June 12, 2020

    Seeams you have an issue with the user. Is a local or remote user?  You can try this:

    diagnose test authserver ldap Dc01 user password

    Then you can validate if its acorrect credentials.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!