Description | This article describes an issue when a user is unable to reach remote subnet when connected to IPsec VPN FortiClient Remote Access due to redundant Group configuration. |
Scope | FortiGate. |
Solution |
There are two ways to configure a user group in a Remote Access Dial-up connection.
IPsec Phase 1 Configuration:
Firewall Policy Configuration:
IPsec Phase 1 Configuration:
Firewall Policy Configuration:
A problem will arise when the user group is defined on both firewall policy and IPsec phase 1 configuration. The IPsec traffic will not match the correct policy and will hit implicit deny.
To diagnose the issue, the administrator needs to run a debug.
diagnose debug flow filter saddr X.X.X.X <----- Specify the VPN IP assigned to the user.
The debug flow output will be like this:
To fix the issue, make sure to follow the guidelines above and configure the user group on either phase1 configuration or firewall policy only. |