Description | This article describes why remote users are unable to authenticate when the SSL VPN firewall policy has 'any' as the source interface. |
Scope | FortiGate, SSL VPN. |
Solution |
If the 'Multiple interface policies' option is enabled under feature visibility, it allows configuring policies with multiple source/destination interfaces or using "any" as a source/destination interface.
If there are multiple policies for SSL VPN using the 'ssl.root' tunnel interface and 'any' as the source interface, the policies with 'any will not be triggered.
In this example, two policies were created:
If a user from the 'SSLVPN_LDAP_admin' group attempts to authenticate, the fnbamd process will exit with a 'Failed group matching' message and the result will return to the SSL-VPN process which will terminate with an 'invalid username/password' message.
[2863] fnbamd_ldap_result-Failed group matching
This could indicate a missing policy for that particular group 'SSLVPN_LDAP_admin'. After changing the source interface from 'any' to the ssl.root interface, it is possible to authenticate with a user that is a member of the 'SSLVPN_LDAP_admin' group.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.