FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rvillaroman
Staff
Staff
Article Id 318606
Description This article describes that Internal users cannot connect to SSL VPN when a limit access coverage to specific hosts or specific geological locations is set.
Scope FortiGate.
Solution

Part of the SSL VPN security hardening is to limit access coverage to specific hosts or specific geological locations.

 

Picture1.png

 

However, it causes SSL VPN internal users to be unable to access the VPN, even under the allowed geo-location.

 

Picture2.png

 

On the packet sniffer, it is possible to confirm that the SSL VPN request is coming from an internal subnet and not from its external public IP; therefore, they are not included in the allowed geolocation.

 

Picture3.png

 

To fix it, include the internal LAN subnet on the limit access to specific hosts.

 

Picture4.png

 

Results:

The internal user can connect to the SSL VPN.

 

Picture5.png