| Description | This article explains the reasons for not detecting a local network after being advertised in the VPN configuration. |
| Scope | FortiGate. |
| Solution |
The user belongs to both the full-access and admin portals in the SSL VPN configuration. Within the full-access local network, which is not advertised, user matching grants full access before matching the admin portal.
Non-working: user is part of both portals.
[188:root:bf8d81d]fsv_saml_auth_group:348 find a remote match group: 3dc6caa8-1435-4698-a448-9b417b5cc41b, portal: Admins, <------------ group: VPN_MFA_ERP.
Working: after removing the user from the Full-Access portal:
[188:root:bf8d06e]fsv_saml_auth_group:348 find a remote match group: 3dc6caa8-1435-4698-a448-9b417b5cc41b, portal: Admins, <---------- group: VPN_MFA_ERP.
Solution: Remove the user from the full-access portal to gain full access to the local network. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.