Skip to main content
Ohop3n
New Member
November 1, 2019
Solved

SSL VPN through two Fortigates

  • November 1, 2019
  • 2 replies
  • 2940 views

hello everybody

 

I have a problem with looping through an SSL VPN connection. The goal should be to register via VPN to the first Fortigate and then to access the subnets of the second and third fortigate.

Construction network: Modem with port forwarding of the VPN connection to the first Fortigate. Each fortigate defines and routes its own subnets. The connection to the second / third fortigate is created via a VLAN. on all fortigates runs RIPv2. on all fortigate's the addresses of the other fortigate's (subnets) are known.

 

From each subnet of a fortigate, the subnetted of the other fortigate can be accessed. this works. VPN connection from an external PC to the first fortigate is established and access to the subnets works. However, I do not come with this vpn connection on the subnets of the other fortigate's.

 

Where can I start for it? The whole thing is constructed as a ring network. later several fortigs will be connected to the ring.

any ideas?

 

 

    Best answer by Toshi_Esumi

    You didn't mention about the subnet of client "SSL-VPN". Check the route for the subnet at 2nd and 3rd FGTs if they've learned via RIP. Then the rest would be combination of "diag sniffer packets" and "diag debug flow" at each FGT; the common troubleshooting process for any routing problems.  I'm assuming, of course, you already checked the routing table on the clients those routes for all subnets were there.

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    November 1, 2019

    You didn't mention about the subnet of client "SSL-VPN". Check the route for the subnet at 2nd and 3rd FGTs if they've learned via RIP. Then the rest would be combination of "diag sniffer packets" and "diag debug flow" at each FGT; the common troubleshooting process for any routing problems.  I'm assuming, of course, you already checked the routing table on the clients those routes for all subnets were there.

    Ohop3n
    Ohop3nAuthor
    New Member
    November 12, 2019

    Problem Solved!

     

    The Clients and FGT's had learned all routes.  The missing peace was a static route at 2nd and 3rd FGT from the SSL-VPN address back to the 1st FGT.

     

    Thanks for the Help!

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!