Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pfc
New Contributor

FGT 30D: SSL-VPN in Forti OS 5.2 = Policy / VPN Client changes

Hi all,

 

i'm about to learn it the hard way, what there have been major changes in 5.2.

I'm following this guide: https://www.youtube.com/watch?v=lqYbNqZSPRA

I understand that there is only one policy needed now, allowing remote clients to connect to the corporate network. However, my client are now bound to the tunnel, and can not surf internet oder do email while beinig connected.

 

I believe this has somehting to do with "enable split tunneling" in SSL-Portal configuration. When i try to enable split tunneling, the forti unit checks and gives back:

 

Failed to save portal. Split tunneling cannot be enabled since IPv4 policy #3's destination address of "all" would be invalid for user/group "sslvpn" (as defined in the SSL-VPN Settings Authentication/Portal Mapping).

 

policy 3 is "ssl.root to lan"

 

to keep it simple:

how can i have my clients using fortclient to dial in (not the webaccess / webportal) and to connect to corporate network while being able to broesw the internet through their own internetconnection (and not using the corporates' one through the tunnel)?

 

thanks a lot in advance

12 REPLIES 12
rwpatterson
Valued Contributor III

According to the upgrade patch document for 5.0.11(http://docs.fortinet.com/...re%20to%205.0.11.pdf), you missed something. It states that from 5.0 GA you need: patch 2(b179) patch 3(b208) patch 4(b228) patch 7(b3608) patch 10(b305) then patch 11(b310) before moving on. You hit: patch 4(b228) something in the middle(b4459) patch 6(271) then patch 10(b305). Quite a few patches were missed. Not sure if there was a patch for the 30D since I no longer have access to those lists. Check again.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
rwpatterson
Valued Contributor III

Found the document for 5.2.2 (http://docs.fortinet.com/uploaded/files/1965/Supported%20Upgrade%20Paths%20for%20FortiOS%E2%84%A2%20...)

 

Patch 2, patch3, patch 4, patch 7, patch 10, 5.2.2.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
pfc

rwpatterson wrote:

Found the document for 5.2.2 (http://docs.fortinet.com/uploaded/files/1965/Supported%20Upgrade%20Paths%20for%20FortiOS%E2%84%A2%20...)

 

Patch 2, patch3, patch 4, patch 7, patch 10, 5.2.2.

you are totally right, according to the upgrade paths, BUT, at least there is no firmware patch  5.03 (build 208) for Fortigate 30D on the download server at https://support.fortinet.com/Download/FirmwareImages.aspx

 

the order i posted above, in my opinion, contains all downloadable firmwareimages from the foritnet servers for a 30D.

so assuming AT LEAST 5.03 is missing, the bug occured.

 

fortinet, confirm anyone? thanks

Labels
Top Kudoed Authors