Puzzled SSL-VPN Interface Behavior
- November 1, 2015
- 1 reply
- 5570 views
Specs: 300c / 5.2.1 GA 618 // have 4 different ssl vpn portals running for over a year.
My policy rule set:
From To Source Destination
ssl.root ssl.root All / (ITAdmin group) Group of IT Admin subnets --- under VPN - ITAdmin portal I have listed the IT Admin subnet group for "routes"
My issues is this, from reading the FGT Cookbook for setting up ssl vpn's when 5.2.1 was released I used 'ssl.root for my 'From & To" interfaces as per my understanding of the document. VPN's worked excellent for over a year and then I would receive reports of staff not able to reach applications that worked in the past. Spoke to FGT and was informed that instead of using 'ssl.root for the 'To" source interface but to use the VLANs that were created. So I dropped ssl.root and replace the vlans, but then I noticed I could not access other items. After doing FGT packet sniff's and packet debugs and seeing nothing wrong with the configuration or dropped packets, I decided to drop all of the VLANs on the interface and replace them with 'ssl.root'. once I did this all of the items I could not access I could again. I receive a different answer everything I speak with FGT. I am perflexed,,,,,,,anyone else experiencing similar issues?
