- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate 200E issue with the VPN
Hello,
I used two fortigate 200E, i have an issue with the vpn.
I'm on the IT team,
I can connect the site with the vpn client (forticlient 7.0.3.0193) but only the files of our serveur file.
No ping is working through the VPN or RDP or anything else except the file of the server file.
I have an administrator acces on the VPN and i allow everything but it isn't working
Here is the configuration of the vpn.
I made a user group "G-SSL-ADMIN" with the users allowed
Screen 1
On SSL-VPN Portals i made a full access group
Screen 2
SSL-VPN Personal Bookmarks.
Someone has an idea ?
 
- Labels:
-
FortiClient
-
FortiGate
-
SSL-VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please share screenshot of SSL VPN setting and configured policy?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
  
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please share configured policy screenshot. I just want to verify if destination and services are allowed in policy or not.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
 
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Where is configured policy ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please make sure all required services like ICMP are present in policy. check the logs for which you are not able to access destination. Run debug flow to troubleshoot issue, it will give you reason for drop. Hop this will help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @User10
You can enable the following debug logs and test again.
diagnose debug disable
diagnose debug reset
diagnose debug cons time enable
diag vpn ssl debug-filter src-addr4 x.x.x.x (Replace x.x.x.x with the IP address of the PC connected to the SSL VPN)
diagnose debug app sslvpn -1
diagnose debug enable
***********reproduce the issue**********
regards,
Sheikh
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Thanks for the reply.
I'm logged on the firewall CLI Console there is no ssh or telnet enable.
When i type : diagnose debug disable
 
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can't make any diagnostic, because the command are not working :
diagnose debug disable
diagnose debug reset
diagnose debug cons time enable
diag vpn ssl debug-filter src-addr4 x.x.x.x (Replace x.x.x.x with the IP address of the PC connected to the SSL VPN)
diagnose debug app sslvpn -1
diagnose debug enable
Someone has an idea ?
