Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
paisakya
New Contributor II

Fortigate GUI not accessible over the Remote VPN

Hi Folks,

 

I am using FortiGate 800-D Firewall and recently setup remote access VPN for the users. The problem what I am facing is that, When I connect remote IPsec VPN through FortiClient then I am not able to access Fortigate GUI(the one with public IP). I am using custom port for GUI, Any thoughts ? 

 

Thank you!

Vishal

10 REPLIES 10
sw2090
Honored Contributor

Did you enable HTTP(S) on your vlan interface?

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
paisakya
New Contributor II

Hi SW2090, Thank you the reply. Yes, Https is enabled on VPN interface
paisakya
New Contributor II

Hi,  Thank you for answer. 

 

I am not restricting with any hosts. even allowed WAN Interface over the VPN but Management GUI is not accessible when I am on remote VPN. I am using custom port instead 443, Is there something needs to be done ? 

 

Thank you!

Vishal

paisakya
New Contributor II

Hi Ashik,

 

Thank you for your reply, You mean to say, not to access GUI directly though public interface ? I have direct public Interface and I need GUI to be publicly accessible. 

 

Thank you!

Vishal

kd007
New Contributor III

VPN interfaces by default are configured with a 0.0.0.0 IP address. Put a static address on the VPN interface and you should be able to manage it on that IP from over the tunnel.

emnoc
Esteemed Contributor III

Agreed, just make sure that the VPN has a  "set allowacess ssh https"  for example

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Prab
New Contributor

paisakya wrote:

Hi,  Thank you for answer. 

 

I am not restricting with any hosts. even allowed WAN Interface over the VPN but Management GUI is not accessible when I am on remote VPN. I am using custom port instead 443, Is there something needs to be done ? 

 

Thank you!

Vishal

Hi Vishal,

 

It should work & it worked on 5.6.4 version for me, I was using Dynamic IPsec VPN with Forticlient.

I assume you might have a routing problem on the remote VPN client. Please make the following checks:

 

1. As mentioned by other users above, assign an IP to the IPsec VPN interface and enable Management access. After the FortiClient has established a connection, try to check the IP address settings received by the remote machine. ("ipconfig -all"  for Windows) You shall see a Default Gateway. Just assign this IP address to the IPsec Tunnel interface.

 

2. Check the routing on the remote machine. It could be that (based on your IPsec VPN config, if Split tunnel is being used) maybe the remote machine is not using the IPsec VPN tunnel at all to access the VPN interface's IP, because the route is missing OR it is using a wrong gateway instead. On windows machine you can use "route print" command to view the routes.

for eg: If the IPsec VPN interface has 10.0.0.3/24 as an assigned IP and the remote client gets an IP 10.0.0.2/24, then the remote client should use 10.0.0.3 as a gateway to 10.0.0.0/24.

 

In IPsec VPN configuration, in case you are using the split tunnel then make sure that the IP address of the IPsec VPN interface is also mentioned there.

 

Please check the traffic logs on the FGT, maybe you could see a reason there?

 

Thanks & regards,

Prab

Ashik_Sheik

Hi,

 

Enable https on LAN or management interface .Don't enable https on  Public interfaces .

 

regds,

 

Ashik

 

Ashu 

 

Ashu
Prab
New Contributor

paisakya wrote:

Hi Folks,

 

I am using FortiGate 800-D Firewall and recently setup remote access VPN for the users. The problem what I am facing is that, When I connect remote IPsec VPN through FortiClient then I am not able to access Fortigate GUI(the one with public IP). I am using custom port for GUI, Any thoughts ? 

 

Thank you!

Vishal

Are you using Trusted Hosts settings under Administrators profile settings? In that case you can only access the Admin GUI from specified IP addresses only!

On FGT GUI -> System -> Administrators

 

Also, check if you are using any local-in policies to restrict the access to FGT.

 

AFAIK: IPsec Tunnel generally has no concerns with the port used by management GUI. Care is required when SSL VPN is being used.

 

Thanks

Prab :)

Labels
Top Kudoed Authors