Hi,
We are using 60F and users connecting there network via forticlient, it was working fine but suddenly issue came is like cant connect there network but client its connected successfully..
Image attached for reference..
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
First thing to do it to check the related traffic logs on the remote FortiGate.
Hi,
Thanks for your reply... please kindly check attached image where can see the details.. or another logs have to check..
Hi
I mean Log & Report > Forward Traffic, then filter source to see traffic from your VPN client.
There you can see if your traffic is blocked and why it is blocked.
If traffic is blocked, you can double-click on the log to see details.
Forward Traffic, then filter source to see traffic from your VPN client..
I tried to find related logs but not getting, Even I tried to make filter Source VPN Client IP & VPN Type...
In order to generate logs, make sure the related firewall rules have "Log Allowed Traffic: All Sessions.
Check sections 1 & 2 in the below link.
Also do the same for "Implicit Deny" policy (0) to see if your traffic is not matching any allow policy.
On the other hand you may also check if your VPN client IP is quarantined, as this may also lead to the same behavior.
diagnose user quarantine list
Yes I select already all session option I tried to enable NAT under that VPN policy so now can see the sent & receiving data .......but not able to access the VPN network..
Now I found logs also & I noticed something also if I will try to open switch or access point in web so that IP will redirect to other IPs...
Main Device IP - 192.168.x.x
Redirect Page IP - http://169.254.1.1:1000/fgtauth?07040c809482fdb0
Hi @kapilkala,
Can you check policy 4 to see why it is being blocked. You mentioned that it is being redirected, do you have captive portal enabled? You can run debug flow to get more information:
di deb disable
di deb res
diagnose debug flow filter clear
di deb flow filter addr 10.0.0.1
diagnose debug flow show function-name enable
di deb flow show iprope en
diagnose debug console timestamp enable
diagnose debug flow trace start 500
diagnose debug enable
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.