Skip to main content
beastiest
New Member
June 15, 2020
Question

SSL VPN client unable to access subnet on other end of P2P tunnel

  • June 15, 2020
  • 4 replies
  • 5611 views

We have a main office and a remote office connected via a point to point VPN connection with a Fortigate at both ends. Work from home employees connect to the main office via SSL VPN using the client software. Those users are able to access resources on the main office subnet but they are unable to access those on the remote office subnet. Users working on site at either office are able to access resources on the other subnet just fine. Have I missed some piece of configuration?

 

Thanks

    4 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    June 16, 2020

    Two questions for your two VPNs.

    1. Do you have NAT set up on the policy (apparently the cookbook was written this way) for SSL VPN to egress interfaces, such as LAN interface and the s2s interface you want to let the SSL VPN users to get to? Or no NAT and exposing SSL VPN user's IP to the destinations?

    2. Does the s2s vpn interface has the tunnel interface IP configured on both ends?

    Depending on the answers you need to take care of things differently.

    beastiest
    beastiestAuthor
    New Member
    June 16, 2020

    Thank for the reply Toshi. Please let me know if these answers are not sufficient.

     

     

    1. We do have NAT enabled on the ssl.root->LAN policy. it isn't enabled on the policies for traffic over the s2s.

    2. On both Fortigates at each end of the s2s vpn we have the IP address of the remote Fortigate configured under VPN->IPsec Tunnels->Network.

    Toshi_Esumi
    SuperUser
    SuperUser
    June 16, 2020

    Then it's simpler for routing.

    1) Check the routing at both FGTs first, if the destination FGT has route back to SSL VPN client subnet.

    2) the policies toward/from the s2s vpn on both sides are allowing the SSL VPN subnet.

    3) s2s phase2 selectors include SSL VPN subnet.

    if still doesn't go across the s2s vpn, you need to sniff (diag sniffer) and run flow debugging for further troubleshooting.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.