Hi Team,
I've configured IPsec IKEV2 VPN with all required configs.
My problem is I can connect without internet because the traffic to the DNS pass through a deny policy as I'm using full tunnel.
I created another test policy on the top of policies but no internet and once I remove the group from that policy I can connect to internet.
Note that the group in that policy is added also in authgrps in the tunnel configs and I'm using FAC in my structure.
This screenshot after removing the group and the internet is allowed.
Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
alaaelrayes,
Seems like the issue is with group matching on FAC. In order to isolate that, Please configure a test local user and check if it works.
Regards
Nagaraju.
local account on FAC or FG ?
I created a local account and a group on FG and I updated that in tunnel authgrp but the same issue.
If I change back the tunnel to IKEV1, it works fine and this issue only with IKVE2.
Issue solved by adding the groups from FSSO.
Thanks all
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.