SSL VPN Being Blocked as Newly Observed Domains
For some reason we could not establish an SSL VPN to other FortiGate firewalls when behind a FortiGate 60F, FortiOS 6.0.9. We are using FortiClient to initiate the VPN connection. The FortiClient response when trying to make the VPN connection was: Warning. Unable to establish the VPN connection. The VPN server may be unreachable. (14). When reviewing the 60F logs in FortiView, under Traffic From LAN/DMZ / Threats, I noticed a a listing of a treat with a Category Newly Observed Domain. This appears to be from the attempted SSL VPN connection. I set the Web Filter and DNS Filter Security Profiles from Block Newly Observed Domains to Allow Newly Observed Domains. Now we can make SSL VPN connections from behind the FortiGate 60F. I don't recall having to set the Web Filter and DNS Filter this way to allow SSL VPN connections before. The addresses we are trying to VPN in to are public IP addresses, and are not not domain names. This blockage happened with numerous SSL VPN connection addresses. Is there something that I am missing that Web Filter and DNS Filter Security Profiles would block VPN connections to public IP addresses?
