Skip to main content
Alexaders
New Member
September 23, 2019
Question

VPN SSL with split tunnel disabled does not work properly

  • September 23, 2019
  • 6 replies
  • 6929 views

Hi everyone, I have a pretty big problem. Then I created an SSL VPN with Split tunnel disabled, the vpn connects and works, but it seems not to resolve the DNS, in fact if I poodle the google 8.8.8.8 dns, I get an "expired request" In practice I wish that when I connect with the VPN, all traffic must pass through the public IP of the firewall. So when I'm going to do a "WhatsMyip", I have to get the IP from the firewall and not my public. I remember that the VPN connects, works and I can also do Google searches, but when I enter any website, it times out. In addition, if I ping with cmd example: ping google.it only resolve ipv6 and not ipv4 .

 

my configuration:

 

 

 

DNS Server is DC01 E DC02

 

 

 

 

So when I go to resolve my ip, on any website, it must be 46.44.xx.xx and not my public ip

 

Thank You Guys

    6 replies

    orani
    New Member
    September 23, 2019

    You need a policy to allow traffic form SSLVPN to wan1 interface and destination all.

    Alexaders
    AlexadersAuthor
    New Member
    September 23, 2019

    orani wrote:

    You need a policy to allow traffic form SSLVPN to wan1 interface and destination all.

    ok so I should change my policy like this:

     

    Incoming Interface : ssl vpn tunnel interface:

    Outgoing inteferface : WAN1

    destination: all

    ????

    orani
    New Member
    September 24, 2019

    No. Do not change the policy you posted above. Create a new one with

     

    incoming interface: sslvpn

    outgoing interface: wan1

    source: same as at your previous rule

    destination: all

    nat: enabled

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.