Can't ping from Internal to SSL-VPN
Hi folks,
I'm a bit new to this, so hoping someone can help. I have our SSL VPN set up and working decently well: remote clients can access internal the (single) internal network resources, and also split tunnels through to external resources (e.g. AWS). So that's working well. The part I'm struggling with is getting the internal network to access VPN clients.
I have a policy set up as such:
-----------------------------------
Incoming Interface: internal
Outgoing Interface: SSL-VPN tunnel interface (ssl.root)
Source: all
Destination: VPN Range
Schedule: always
Service: All
Action: Allow
(This is in addition to the regular SSL-VPN -> internal/wan policies that are working as expected right now)
Internal IP Range: 10.0.1.0/24
VPN IP Range : 10.0.2.0/24
Ping from SSL VPN to Internal is fine (e.g. 10.0.2.123 -> 10.0.1.123)
Ping from Internal to SSL VPN times out (e.g. 10.0.1.123 -> 10.0.2.123)
When I ping from internal to the SSL VPN resource, I can see in FortiClient that the resource is receiving/sending data, and the firewall logs (Windows 10) also shows the ICMP allowed and received:
2019-11-10 11:21:48 ALLOW ICMP xxx.xxx.xxx.xxx 10.0.2.2 - - 0 - - - - 8 0 - RECEIVE
I'm at a bit of a loss, not sure how to proceed from here. Any help would be really appreciated.
Best,
Graf
