Skip to main content
JBruyet
New Member
December 21, 2015
Question

Fortigate 80C and I lost VPN capability for SSH and Web

  • December 21, 2015
  • 10 replies
  • 11261 views

Hey all, in the past I've been able to VPN into work from home and SSH to my Linux servers and access my web-based programs but not any more -- when I try to access these things the connection times out.  I haven't had to do anything like this for a while so I'm not sure when I lost this capability. I can still RDP into my Windows servers and workstations without any problems so I'm guessing it's configuration issue but no one has touched it - it's behind a locked door with badge access only. The guy who was in charge of the FortiGate 80C has moved on so now it's my responsibility to get it working again. Any ideas on what would have changed and how to get that access restored? I'm not sure where I should even start looking. I was going to start by power-cycling the FortiGate but I was told that power-cycling it could introduce new issues so I'm holding off on that.

 

Thanks,

 

Joe B

    10 replies

    ede_pfau
    SuperUser
    SuperUser
    December 21, 2015

    hi,

     

    sounds funny.

    I assume your side (the client's) is via software VPN client.

    So the only place you have to check are:

    - on the HQ FGT the policy from tunnel to internal (i.e. the interface your servers are connected to), especially the 'service' entry

    - whether there are VIPs defined, and if so, if they could interfere with the port used (std is 22 but that may be any)

     

    Visual inspection of the policy ruling the traffic from tunnel to LAN should suffice to spot the misconfig. If that doesn't help you can always diagnose the traffic flow (diag deb flow ...) as described here in the forums a hundred times (search for "debug flow" and "emnoc" :)

    But I'd start with the easier part.

    JBruyet
    JBruyetAuthor
    New Member
    December 21, 2015

    Hi ede_pfau,

     

    - on the HQ FGT the policy from tunnel to internal (i.e. the interface your servers are connected to), especially the 'service' entry

    [ul]
  • I found 17 entries, Policy Objects > Policy > IPv4, & every entry’s “service” field says ALL
  • Also, Policy & Objects > Objects > addresses, the Pptp address shows a Subnet / IP Range of x.x.x.120-x.x.x.121. Those addresses are for two hosts in my VMware cluster. What’s up with that???[/ul]

    - whether there are VIPs defined, and if so, if they could interfere with the port used (std is 22 but that may be any)

    [ul]
  • I found Policy & Objects > Virtual IPs but these are just standard port forwarding configurations [/ul]

    But I'd start with the easier part.

     

    Well, I guess I'm going to have to go to the next level because I didn't see anything here that would help me. The comment about "Visual inspection of the policy ruling the traffic from tunnel to LAN should suffice to spot the misconfig" wasn't very much help because I don't know what to look for. I'll move on to diagnosing the traffic flow and see if I can find something there.

     

    Thanks,

     

    Joe B

     

  • ede_pfau
    SuperUser
    SuperUser
    December 22, 2015

    Joe,

     

    sorry, no offense intended. The info about your config is so thin that I'm afraid help could be very difficult. If I interpret your last post correctly, "VPN" is not IPsec VPN nor SSL VPN but PPTP??

    Crucial information like that cannot be left out if you expect substantial help.

    My remark about a glance over the policy table is quite serious and, as I see now, feasable. It's not 17 policies that you need to check but the one or two which rule the traffic flow between the tunnel and your LAN. From that summary statement you made I assume that you're very fresh with FortiOS and in need of the basics: how traffic flow is structured, how policies are made and in which sequence, the different kinds of VPN etc. etc.

     

    Of course you can take the shortcut and debug something. Without some basic understanding of FortiOS it probably won't tell you much. And without a (more) complete view of your configuration we can't tell much either. Go for it anyway.

     

    For more background: docs.fortinet.com , esp. the Handbook (complete reference with examples), the CLI Reference, the Cookbook (most common example "recipes"). And of course the Knowledge Base (kb.fortinet.com).

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!