parthpatel
Staff
Created on
04-12-2023
10:24 PM
Edited on
09-05-2024
11:10 PM
By
Anthony_E
Article Id
252222
Description
This article describes that if the SSL VPN settings are already configured on the FortiGate running NGFW policy-based mode and have the policy under security policy, it still sends the error message stating 'Permission Denied' as the screenshot below.
Scope
FortiGate.
Solution
- Within the Central SNAT section apply a policy the NAT option is disabled for this internal traffic.
- Check the ‘SSL Inspection and Authentication’ policy because if the policy is already configured under ‘Security Policy’ it will only be referred for UTM features.
- To allow the traffic to pass through, it is necessary to configure the group under the ‘SSL inspection and Authentication’ as in the image below. This will ensure that VPN users are being authenticated properly while logging in.
-
Under this ‘SSL Inspection and Authentication,’ all the user groups need to be added.
Once the user group is added here, FortiGate will be able to authenticate the user without any issues.