Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
LookersGroup
New Contributor

Fortigate SSL VPN and Akamai

Hi,

 

Has anyone had any experience using Akamai in front of a Fortigate SSL VPN endpoint?

 

So far we have done the following. - Allowed the Akamai subnets as allowed hosts in the SSL VPN settings on the Firewall - For testing purposes edited the clients local host file to resolve the FQFN to the IP of the Akamai endpoint The Fortigate logs for the users says tunnel-down 'User requested termination of service' when it disconnects. We do note that when the Client connects the remote host IP as an Akamai IP and not the clients public IP which is why I think the client disconnects.

 

Does anyone managed to get this working and if so how?

 

Many Thanks

4 REPLIES 4
Jean-Philippe_P
Moderator
Moderator

Hello LookersGroup, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello again,

 

I found this solution. Can you tell me if it helps, please?

 

To address the issue of SSL VPN disconnections when using Akamai endpoints, follow these steps:

 

  1. Verify Configuration: Ensure that the Akamai subnets are correctly configured as allowed hosts in the SSL VPN settings on the FortiGate. Double-check the entries for any typos or misconfigurations.

  2. Hosts File: Since you've edited the client's local hosts file for testing, ensure that the FQDN resolves correctly to the Akamai endpoint IP. This should match the IP address that the FortiGate expects.

  3. Check Logs: The log message "user requested termination of service" suggests that the client might be initiating the disconnection. Investigate the FortiClient logs to see if there are any errors or warnings that could indicate why the client is disconnecting.

  4. Akamai IP Recognition: If the remote host IP is recognized as an Akamai IP instead of the client's public IP, ensure that the FortiGate is configured to accept connections from these IPs. This might involve adjusting the SSL VPN settings to accommodate the Akamai IPs.

  5. Network Address Translation (NAT): Consider using NAT to ensure that the client can access remote resources without IP conflicts. This can help if there are overlapping subnets or if the Akamai IPs are causing issues.

  6. Consult Documentation: Review any Fortinet documentation or community posts related to using Akamai with FortiGate SSL VPNs for additional insights or configuration tips.

 

If the issue persists, consider reaching out to Fortinet support for further assistance, as they may have more specific guidance based on your configuration and network setup.

Jean-Philippe - Fortinet Community Team
filiaks1
Contributor II

The MTU over public networks can't be controlled and from my experience many have issues with TLS/SSL/DTLS or ipsec VPN over things like Akamai , Cloudfront or F5 XC Distributed Cloid.

 

Why you are trying to this in a first place is a good question ?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors