Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
drabbert
New Contributor

Authentication failure on SSL-VPN

Hi, I' m trying to setup a SSL-VPN to my FortiWifi 60D and get a loging failure when I' m try to login. The logging says: Administrator Erwin login failed from https(.....) because of invalid user name So it seems that I' m trying to connect to the Admin page with my VPN user. Could someone help me on this and tell me how I should connect the SSL-VPN portal? Thanks.
With kind regards, Erwin
With kind regards, Erwin
15 REPLIES 15
Dipen
New Contributor III

What is your user database.. Its local or Remote [LDAP]. Also whats your SSL-VPN port ? You should set it to 10443 preferably If you want to use simply 443 for SSL-VPN then please change default admin port to 4433 instead of 443. What page are you getting when u punch-in URL in browser.. Admin Login Page & SSL-VPN login page are easily distinguishable.

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
emnoc
Esteemed Contributor III

what port is you SSLVPN bound to? What interface ? e.g diag sys tcpsock | grep 0.0.0 Look at the 0.0.0.0 and find you port or modify it in your ssl configurations. It seems like you have a conflict on the port your accessing. So I would check the client URL or port-setting

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dipen
New Contributor III

In fortiOS 5.2 finally they have given the port-binding for SSL-VPN in GUI In earlier versions what is the command to do that ?

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
Dipen
New Contributor III

Please use different port for Admin GUI & SSL-VPN ..Ports Nos are up to you no hard requirements ;)

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
drabbert
New Contributor

Thank you all for your replies. I' ve changed the port for the admin page and left the port of de ssl portal to 443. The admin page works on the new port, the ssl portal does not show up. So the ssl portal page seems not be working, do I have to enable it somewhere or need I bind it to the WAN interface?
With kind regards, Erwin
With kind regards, Erwin
emnoc
Esteemed Contributor III

yes you need to configure it in the settings it' s enabled by interface in the WebGUI

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dipen
New Contributor III

I heard that prior to FortiOS 5.2 the interface binding was possible through CLI. I searched CLI Reference Guides but couldn' t find it. any suggestions for FortiOS 5.0.x,

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
drabbert
New Contributor

I cannot find this in the GUI, where could I find this? Do you know the CLI commands for this setting? The documentation says: The SSL VPN settings page, found at VPN > SSL > Settings , has been reorganized to be more intuitive. The settings are now found in the following sections: • Connection Settings define how users connect and interact with an SSL VPN portal. This section includes Listen on Interface(s), Idle Logout, and Server Certificate. But in the Gui of my ForiEifi 60D I cannot find ths, also the structure of the menu is different: VPN -> SSL -> Config I can set the port but I cannot bind interfaces
With kind regards, Erwin
With kind regards, Erwin
emnoc
Esteemed Contributor III

What version of OS are you running? The above is from 5.2 GA CLI cmd configuration; config vpn ssl settings set tunnel-ip-pools " SSLVPN_TUNNEL_ADDR1" set tunnel-ipv6-pools " SSLVPN_TUNNEL_IPv6_ADDR1" set port 10442 set source-interface " internal1" " internal3"

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors