Description
This articles describes how the SSL VPN client needs to communicate with another SSL VPN client.
Solution
Create a new policy as shown below.
If split tunnel is enabled in the SSL VPN, add the SSVPN client subnet to the routing address list in the respective SSL VPN portal.
After making changes, test the SSL VPN client-to-client communication.
Make sure the client windows firewall allows this communication.
If the issue is not resolved at this point, open a support ticket in the Fortinet support portal and attach the following:
ipconfig /all
route print
tracert <remote sslvpn client>
diagnose debug reset
diagnose debug flow filter addr x.x.x.x <----- Replace x.x.x.x with the source SSL VPN client IP.
diagnose debug flow filter proto 1
diagnose debug flow trace start 10000
diagnose debug enable
After running the commands, initiate the ping from the client PC.
Later, disable the debug processes with the following commands:
diagnose debug reset
diagnose debug disable
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.