Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Infotech22
Contributor

FortiEMS/FortiClient - VPN Tunnel with Multiple Gateways, Security Alert

Hello,

I have a strange behavior with our FortiClient's tunnels.

  • Created a Remote Access profile on our FortiEMS, it's a VPN Tunnel with 4 remote gateways.

  • Created DNS records for our public IP addresses from FortiGates via Let'sEncrypt.

 

 

Now when I try to connected to that one tunnel it will prompt me the "Security Alert" on 40% before it makes the connection.

But if I create 4 separate tunnels and not 1 tunnel with multiple gateways then I don't get the prompt with "Security Alert", the connection is established normally.

Does anybody have a clue what this can be, probably some limitations with multiple gateways..

1 Solution
ozkanaltas

Hello @Infotech22 ,

 

This problem is related to IP addresses. If you use an IP address instead of fqdn this warning will be shown. Can you try just with fqdn? 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
6 REPLIES 6
ozkanaltas
Contributor III

Hello @Infotech22 ,

 

All configured GW addresses configured with fqdn? Do you have any gw addresses configured with IP addresses?

 

Or maybe your FortiGate could not renew your certificate. Can you check your SSL certificate? You can use this tool to check your ssl-certificate.

 

https://www.ssllabs.com/ssltest/

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Infotech22

Hello @ozkanaltas,

Thank you for replying.
No, only first 2 Gateways are configured with FQDN.
They are order from FQDN to IP Addresses, so first 2 are FQDN

I double checked Certificates and they are trusted

ozkanaltas

Hello @Infotech22 ,

 

This problem is related to IP addresses. If you use an IP address instead of fqdn this warning will be shown. Can you try just with fqdn? 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Infotech22

Hi @ozkanaltas,

When removed both IP addresses from tunnel then its working.
I can create DNS records for those 2 Failover IP address but how would I approach it because on the FG we can only choose one certificate for SSL-VPN?

Thank you for solutions

ozkanaltas

Hi @Infotech22 ,

 

Fortigate can't support creating a wildcard certificate or multiple fqdn ssl certificates with acme. If you used this way you can't achieve this.

 

You can buy SSL certificates from trusted authorities. Or you can create manually a wildcard certificate with letsencrypt.

 

You can review this document on how to create a wildcard certificate with letsencrypt.

 

https://www.linkedin.com/pulse/wildcard-certificates-using-lets-encrypt-certbot-pallavi-udhane

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Infotech22

Hi @ozkanaltas,

Thank you very much for all the help you provided.

Labels
Top Kudoed Authors