Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
khee
New Contributor

Does anyone know why from Canada to US firewall, IPv4 is not allowed ? Is it because international ?

VPN connection via IPv4 from Canada to US Fortigate is not allowed weirdly. 

Anyone has an idea why ? 

And if no workaround is there, do I need to relocate to US to work for US company ? not remotely from Canada ?

If I use a Windows VPN like CyberGhost, it works, but there are DNS problems, ping fail, and so on, so I cannot access anything and doesn't make a difference a lot.

3 REPLIES 3
Toshi_Esumi
Esteemed Contributor III

We have several customers who have their locations in BC, AB and ON in Canada connected to our FGTs on U.S. side over IPSec VPN. If your location doesn't connect, first you need to prove some specific types of packets, like UDP 500, 4500, or ESP (if IPsec), or TCP 443, 10443 (if SSL VPN) that is coming out of the client/FGT device in CA, and it's not reaching to the server FGT in the US. Or, opposite direction. Then fight with your local ISP in CA why they're blocking with the fact in hand.

In any case, it should have nothing to do with FGTs.

 

Toshi

khee
New Contributor

It is SSL port 444 and you mean that the Canadian ISP is blocking that port ?

I think you are right because if I use CyberGhost and use an IP in Seattle it can connect.

But CyberGhost is not allowed to work with FGT, right ?

Thanks.

Toshi_Esumi
Esteemed Contributor III

Port 444 is for SNPP(https://en.wikipedia.org/wiki/Simple_Network_Paging_Protocol). You shouldn't be using it for SSL VPN. Change it back to the default 443 or use a high number port like 10443, which was previous default on FGT.

When you sniff on the FGT side if it's coming while you're attempting to connect, then if you don't see anything coming in, it must be blocked.

I have no idea what CyberGhost does. But I assume it's just a vpn to hide your local IP and encrypt through local ISP and other networks before hitting the CyberGhost's server. It has nothing to do with your FGT. But if you connected to the FGT with a VPN, depending on the setting it does the same thing: encrypt traffic until gets to the FGT, then it might go out to the internet with the FGT's IP.

 

You sounded like you didn't manage the FGT but just an SSL VPN user. Talked who manages the FGT.

 

Toshi

Labels
Top Kudoed Authors