Description | This article describes which destination addresses and services need to be allowed on Upstream devices. |
Scope | Fortigate, Fortitoken, 2FA |
Solution |
Suppose there is a downstream FortiGate which having limited connectivity to the internet but want to implement SSL VPN with FortiToken 2FA on the downstream Firewall.
Topology: WAN ---- FW1 [Upstream] <-------> FW2 [Downstream]
The 1st setup requires points 1 (to send an email to the user) and 2 (to communicate with the FortiToken server) is required. SSL VPN connection should works after this. |