- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate SSLVPN TEAM
Hi, everyone
I have the following problem.
FortiVM02 customer arrives in a full tunnel with SSLVPN.
If the customer has video conferences via Teams, this does not work. Team breaks down.
In the office without SSLVPN it is not a problem.
I have SIP ALG disabled.
Have any of you experienced this yourself or know where the dog is buried?
Greeting
Christian
- Labels:
-
FortiClient
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Did you mean that all traffic from client would reach FortiGate (ie, no split tunneling used)? If so, is there a policy from ssl interface to wan interface? And if it did, does it have any security profiles?
Best regards,
Jin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Jin I set up a full tunnel. I have no sec on the rule of SSLVPN-> WAN. profile active.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Are you using SDWAN if you can you create a rule with a Single interface only for the SSL VPN users and check
Regards,
Vishal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Vsahu
I don't use SDWAN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Can you create a new policy on the top of the existing one for the SSL VPN Teams Access, Use Internet service as a Destination and add the Microsoft-Skype_Teams. Disable all the UTM and check the behavior.
Vishal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Vsahu
I configured the rule to any.
Isn't that the same as configuring the Internet Service?
I have now created a rule with the Internet Service.
Greeting
Christian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Christian,
If you had the policy with All as the destination it should not cause any issues with the respected traffic, but it's sometimes better to segregate the Services which are having the issue and check the behavior that's why I suggested the same.
Vishal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Christian,
If your company allows, you can also enable split tunneling. In this way, only the LAN traffic will traverse via SSL VPN while the Internet traffic will go via local Internet of the connected user.
SFA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Team,
SIP alg is not related to microsoft teams.
If you experience teams call issue with ssl vpn, that could be because of bandwidth issue.
Can you create interface widget for wan interface
You can use this article and check for interface bandwidth widget.
Also, can you check if there is any DOS policy configured for the firewall?
