Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smxko
New Contributor III

First IP on SSL-VPN has no network access

Hi,

we use SSL-VPN with FortiClient via Entra ID SAML. We have 3 Entra groups for accessing SSL-VPN. The IP range for all clients on SSL-VPN is 192.168.15.1 - 192.168.15.254.

 

Strangely, when a clients gets the assigned the IP 192.168.15.1, FortiClient connects but there's no network access. Bytes sent / received in FortiClient is only a few kbytes. When I view the logs, I see that the Client mostly only does DNS / LDAP requests to our domain controller. But no SMB to our fileserver or whatsoever. When I try to run ICMP to the domain controller, I get a timeout. Wierdly enough, under forward logs I see "PING ACCEPT (240B / 240B) - so from FGT's perspective, it replies to the ICMP request done by 192.168.15.1.

 

I also ran Wireshark on the client and there it gets eaven crazier. When I monitor the SSL-VPN interface, I only see the ICMP reply from the domain controller to the client but not the ICMP request leaving through the SSL-VPN interface.

 

This happend on multiple devices but not on all of them, always when the .1 was assigned. That address is not used anywhere else on the network. I also checked FGT's FIB, the address is not in conflict. As a workaround, I set the assigning IP range starting from 192.168.15.2. But what could possibly be the culprit here? It might be a local problem but I already checked IP conflicts via "route print" and "Get-NetIPAddress" but the IP always was unique to the Fortinet SSL VPN Adapter.

 

 

12 REPLIES 12
smxko
New Contributor III

Nope, not on my end. We sticked to using the workaround starting with the .2

CBBG55
New Contributor

Same here.

FortiOS 7.2.11 Forticlient 7.4.3 or 7.2.10

The issue happen only on Windows 11 24H2 PC

filiaks1

Strange maybe see if ifconfig/route print and nslookup on Windows 11 24H2 PC  and maybe upgrade the forticlient.

 

 

Also if you have split tunnel maybe stop it just for the testing.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors