Skip to main content
Contributor III
August 17, 2011
Question

RDP connection through SSL VPN portal

  • August 17, 2011
  • 9 replies
  • 10762 views
Hi, I have successfully created an SSL VPN connection to our Fortigate 110C running v4.0,build0303,101214 (MR2 Patch 3). I can connect to everything correctly as specified in the firewall rules, including an RDP session to a server. What I would like to do is use the portal and the bookmark widget to save and give users direct access to the stored RDP connection. I was able to create the connection but when I try and initiate it the following error is returned after clicking OK on the screen resolution, " RDP Error" " Connection Exception" " SSL negotiation failed, please check your Fortigate configuration" What and where do I check? Thanks for any advice.

    9 replies

    ddskier
    New Member
    August 18, 2011
    Dumb question... Did you create the SSLVPN policies that allow the RDP access to the servers? (e.g. Type SSLVPN)
    Contributor III
    August 18, 2011
    Yes, the policies are there. I can connect to an RDP session when the VPN connection is initiated using the Windows Remote Desktop program. What I cannot do is connect through the web browser portal window with the bookmarks widget.
    rwpatterson
    New Member
    August 18, 2011
    The web widgets use straight through policies. No need for ssl.root. Wanx -> internal. ssl.root is only for tunnel mode. No need even to ' connect' with the web widgets.
    Contributor III
    August 18, 2011
    Yes, I realize that too. But it will not connect with the widget, connected or not it returns the same error.
    jmac
    New Member
    August 18, 2011
    Allowed destinations for the web portal are determined by the destination IP/ranges set in the Allow:SSL-VPN firewall rule. You need to make sure your RDP destination is covered by an assigned range in the rule. If your destinations include multiple interfaces (e.g. from WAN1 to Internal1 and from WAN1 to Internal2), then you need a SSL-VPN rule for each interface pair with appropriate destination IP ranges specified in the rule. Note, this for the SSL-VPN rule, not ssl.root tunnel rules.
    rwpatterson
    New Member
    August 18, 2011
    Your source IP address should be the wildcard (any, or 0.0.0.0)
    Contributor III
    August 19, 2011
    jmac: Destinations are all specified in the rules. rwpatterson: Yes, that is the source range. Thanks for the replies.
    rwpatterson
    New Member
    August 19, 2011
    Crappy code?
    Arkadiusz
    New Member
    September 15, 2011
    Hello. How to configure SSL VPN Connection + RDP Windows. SSL VPN itself works me vpn tunnel-mode-mode but with this I can not help myself EDIT ' " Yes, the policies are there. I can connect to an RDP session when the VPN connection is initiated using the Windows Remote Desktop program" How did you managed to do it?
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!