Description | This article describes an issue when a user is unable to reach remote subnet when connected to IPsec VPN FortiClient Remote Access due to redundant Group configuration. |
Scope | FortiGate. |
Solution |
There are two ways to configure a user group in a Remote Access Dial-up connection.
IPsec Phase 1 Configuration:
Firewall Policy Configuration:
IPsec Phase 1 Configuration:
Firewall Policy Configuration:
A problem will arise when the user group is defined on both firewall policy and IPsec phase 1 configuration. The IPsec traffic will not match the correct policy and will hit implicit deny.
To diagnose the issue, the administrator needs to run a debug.
diagnose debug flow filter saddr X.X.X.X <----- Specify the VPN IP assigned to the user.
The debug flow output will be like this:
To fix the issue, make sure to follow the guidelines above and configure the user group on either phase1 configuration or firewall policy only. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.