Skip to main content
Zoxan
New Member
January 10, 2024
Question

VPN traffic blocked by implicit deny

  • January 10, 2024
  • 5 replies
  • 3139 views

Hi guys! Here is a issue with Fortigate200F(7.4.1) - ipsec vpn lpdap users randomly cant get access(cant even ping) to various internal sources after establishing connection cause of sudden implicit deny, locally created users have no such problem at all though. They both are in the same group, under same policy. Its strange how that rule doesnt work for AD users sometimes. Any guesses?

5 replies

AEK
SuperUser
SuperUser
January 10, 2024

Hi

Does the related policy use FSSO as source?

I guess the blocked traffic shows IP without user, right?

AEK
Zoxan
ZoxanAuthor
New Member
January 11, 2024

@AEK wrote:

Hi

Does the related policy use FSSO as source?

I guess the blocked traffic shows IP without user, right?


The policy contains VPN ip range and group of imported ldap users with local users as source. Blocked traffic shows Source/Source Country/Region/Source Interface/Device ID/User in details, when Accepted - same with addition of Source NAT IP/Source NAT Port and Group

dbu
Staff
Staff
January 11, 2024

What do you mean by: The policy contains  "group of imported ldap users with local users as source" ?

Are you using IKEv1 or 2 ?  

hbac
Staff
Staff
January 10, 2024

Hi @Zoxan

 

Do you mean IPsec VPN users are able to connect but can't access internal resource? You need to run debug flow to see why it is being dropped: https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connectivity/ta-p/192560

 

Regards, 

sahmed_FTNT
Staff & Editor
Staff & Editor
January 14, 2024

Hello, if you can share debug output that will be more useful to troubleshoot

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.