Skip to main content
kssupport
Visitor III
October 6, 2020
Solved

Internet access for VPN SSL CLIENT

  • October 6, 2020
  • 5 replies
  • 5470 views

hello there,

please help.

we using FG30E with firmware 5.6.12

we have created vpn ssl with tunnel mode, and client can connect successful.

we have create 3 policies (as shown video tutorial):

- WAN to VPN SSL, I don't think this have problem, since client can connect to vpn ssl.

- VPN SSL to LAN, I assume this has no problem, since client can access LAN after connect vpn ssl.

- VPN SLL to WAN, with configuration:

source: all IP, list of users vpn

destination: all

service: all

NAT: ON

AV: ON

accept connection.

 

fortigate restarting. client connect to vpn ssl, success.

but client can't access internet (trying browsing any website).

 

need help please. thank you

    Best answer by sw2090

    you shouldn't allow wan to vpn. This is creating security whoes and you do not really need it.

    for internet you need vpn to wan so that's ok. Does the client have a default route to your FGT over the vpn?

     

    5 replies

    sw2090
    SuperUser
    sw2090Answer
    SuperUser
    October 6, 2020

    you shouldn't allow wan to vpn. This is creating security whoes and you do not really need it.

    for internet you need vpn to wan so that's ok. Does the client have a default route to your FGT over the vpn?

     

    kssupport
    kssupportAuthor
    Visitor III
    October 7, 2020

    hello.

     

    noted. wan to ssl already deleted.

    thanks

     

    Does the client have a default route to your FGT over the vpn --> do we need to create static route for this?

    source : all, gateway: gateway FG (internet), interface ssl root?

     

    sw2090
    SuperUser
    SuperUser
    October 7, 2020

    Not on the FGT. The Route must be clientside.

    Since we don't use SSL VPN I can't say much about how to push routes with it.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.