Description | This article describes how to resolve the issue in which FortiClient or SSL VPN Client is assigned with an IP address that does not come under the specified SSL VPN IP address range under SSL VPN Settings. |
Scope | FortiGate SSL VPN. |
Solution |
If a FortiClient receives an IP address outside of the SSL VPN IP address range.
Confirm the IP address range under SSL VPN Settings if it is the required one or not.
If the IP address range under SSL VPN Settings is correct, check the Source IP Pool under SSL VPN Portal, the Source IP Pool Address Range must be the same as the SSL VPN Address Range under SSL VPN Settings.
To check the address range through the CLI run the following commands:
FortiGate3 (root) # config vpn ssl settings FortiGate3 (settings) # show end
FortiGate3 (root) # config vpn ssl web portal FortiGate3 (portal) # edit "full-access" |