Description |
This article describes that the address range configured under ‘config authentication-rule’ will take precedence over what is configured under ‘config vpn ssl settings'.
Example:
config vpn ssl settings
config vpn ssl web portal
config firewall address
config firewall address
In the above configuration, the user connects successfully and the obtained IP comes from the SSLVPN_TUNNEL_ADDR1 address group since it is the one configured under ‘config authentication-rule’. |
Scope | FortiGate. |
Solution |
To get the correct IP, always check and verify what is the address range under ‘config authentication-rule’ and configure it as necessary. Always check the 'tunnel-addr-assigned-method' parameter under the SSL VPN setting. This can only be checked via CLI.
config vpn ssl settings
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.