SSL VPN Web Portal Access Issue
New to Fortinet. Trying to get our new Fortigate 60E (5.4.6) setup and tested before putting it into production. Everything seems to be working except for web based SSL VPN access to an internal web server. I can get to it if I connect with the FortiClient.
- When trying to connect to the Fortigate admin console I get "Secure Connection Failed". (Not sure if you can connect to the admin console that is providing the VPN)
- When trying to connect to the admin console of a wifi access point, I never get a response. It is waiting forever. Partial debug logs below:
[15718:root:0]ap_write,203, error=Broken pipe. [15718:root:17f]Destroy sconn 0x546d9300, connSize=1. (root) [15718:root:181]SSL state:warning close notify (192.168.99.108) [15718:root:181]sslConnGotoNextState:299 error (last state: 1, closeOp: 0) [15718:root:181]Destroy sconn 0x546d9c00, connSize=0. (root) [15719:root:181]allocSSLConn:276 sconn 0x54647c00 (0:root) [15719:root:181]SSL state:before/accept initialization (192.168.99.108) [15719:root:181]SSL state:SSLv3 read client hello A (192.168.99.108) [15719:root:181]SSL state:SSLv3 write server hello A (192.168.99.108) [15719:root:181]SSL state:SSLv3 write certificate A (192.168.99.108) [15719:root:181]SSL state:SSLv3 write key exchange A (192.168.99.108) [15719:root:181]SSL state:SSLv3 write server done A (192.168.99.108) [15719:root:181]SSL state:SSLv3 flush data (192.168.99.108) [15719:root:181]SSL state:SSLv3 read client certificate A (192.168.99.108) [15719:root:181]SSL state:SSLv3 read client key exchange A:system lib(192.168.99.108) [15719:root:181]SSL state:SSLv3 read client key exchange A:system lib(192.168.99.108) [15719:root:181]SSL state:SSLv3 read client key exchange A (192.168.99.108) [15719:root:181]SSL state:SSLv3 read certificate verify A (192.168.99.108) [15719:root:181]SSL state:SSLv3 read finished A (192.168.99.108) [15719:root:181]SSL state:SSLv3 write session ticket A (192.168.99.108) [15719:root:181]SSL state:SSLv3 write change cipher spec A (192.168.99.108) [15719:root:181]SSL state:SSLv3 write finished A (192.168.99.108) [15719:root:181]SSL state:SSLv3 flush data (192.168.99.108) [15719:root:181]SSL state:SSL negotiation finished successfully (192.168.99.108) [15719:root:181]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [15719:root:181]req: /remote/portal?action=2 [15719:root:181]deconstruct_session_id:363 decode session id ok, user=[chet],group=[SSL-VPN-users],portal=[full-access],host=[192.168.99.108],realm=[],idx=0,auth=1,sid=6b6a71f5, login=1511541944, access=1511541944 [15719:root:181]deconstruct_session_id:363 decode session id ok, user=[chet],group=[SSL-VPN-users],portal=[full-access],host=[192.168.99.108],realm=[],idx=0,auth=1,sid=6b6a71f5, login=1511541944, access=1511541944
Any troubleshooting help would be appreciated.
