Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Drkrieger
New Contributor

Issues seeing remote computers through SSL VPN

Hello! I am experimenting with an older Fortigate 60B (running FortiOS 4.0 MR3, Patch 15) that my boss gave me and I' m trying to learn how to setup an SSL VPN. I found a few videos on how to configure the unit to do web filtering for remote clients and adjusted to configuration to provide VPN access to the internal network. Basically, I' m trying to use the SSL VPN to gain file share access on my home network for remote computers. I have been able to configure the VPN so that I was able to log in using the Forticlient (version 5.2), but I' m not able to ping or file share (SMB/CIFS) even though it is enabled in the portal. Here' s how I have it configured: 1. Set up the user accounts (the internal network is a workgroup, no AD) 2. Created user group, set VPN Access to ' full-access' 3. Adjusted SSLVPN_TUNNEL_ADDR1 to a range other than default (FW Objects) 4. Created address range for my internal network (FW Objects) 5. Under VPN->SSL->Config, added SSLVPN_TUNNEL_ADDR1 to IP Pools 6. Under VPN->SSL->Portal, made sure all applications were checked (settings) 7. Added the adjusted IP range for the SSLVPN address range to Static Routes attached to device: ssl.root 8. Created Policy for WAN1->SSL.ROOT, Allowed all source addresses, destination addresses are SSLVPN range, action as SSL-VPN, added user group with all services allowed 9. Created Policy for SSL.ROOT->Internal, SSLVPN address range source, Internal home network range as destination, service any, Action allowed, NAT Enabled (also tried with this disabled, still no go) I have no issues connecting to the VPN, that goes smoothly. I am unable to ping or directly look at any machines file shares (using Windows explorer and typing \\<ip address> of machine). Is there a step I may have missed? Or a setting I need to adjust? I can provide screenshots of my policies if required. Thanks in advance!
13 REPLIES 13
oheigl
Contributor II

Hello Bob, the problem is he is using split tunnel, so he must configure the internal network also in the SSL-VPN rule, otherwise the client doesn' t know where to send this packets, and just sends them to his local gateway on the client network. If he would send us a route print output of the client while connected, we would see exactly this issue. Kind regards, Oliver
Drkrieger
New Contributor

Well, still no go on the SSL. Here' s a route print. The 108.173.119.107 is the destination, but the gateway is wrong. It' s using my current gateway (on the machine running the Forticlient). Should it not be pointing to the gateway on the home internal network?
Drkrieger
New Contributor

I appear to have resolved the issue! I added a policy to allow Internal->SSL.Root. Once I did this, everything worked! Thank you all for the assistance, it was really appreciated :)
Lacory

Drkrieger wrote:
I appear to have resolved the issue! I added a policy to allow Internal->SSL.Root. Once I did this, everything worked! Thank you all for the assistance, it was really appreciated :)

Hi Drkrieger,

 

I am still new in this world of FortiOS, can you please provide with the steps of the above.

 

I am currently sitting with the similar problem, my SSL VPN connection works up until the WebPage/Client, I am unable to see anything sitting behind the firewall, however I can ping the devices from the WebPage using the Connection Tools.

 

Thanks

Lacory

 

Labels
Top Kudoed Authors