Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
NitroXIII
New Contributor

Installing OpenVPN client behind Fortigate

Hi all,

 

I'm trying to connect to an OpenVPN access server (outside our network) from a machine behind our Fortigate 60D firewall. The connection is established, however any communication aside from that seems to be blocked in some fashion.

 

Currently the OpenVPN access server is attempting to access our SQL Server, and also trying to just send a ping request to our machine (this is for a website) with the OpenVPN Client installed, but the OpenVPN Access Server isn't getting any response from our machine behind the firewall. This configuration has been tested on other networks that aren't behind a Fortigate Firewall, and we're just hoping that someone here might have a clue.

 

Does anyone know if there's some settings I need to enable? Do I need to allow tunneling somehow? I'm kind of lost here, any help is appreciated.

 

Thanks,

Dylan

2 REPLIES 2
emnoc
Esteemed Contributor III

The cli cmd diag debug flow is your friend. ;)

 

If the client is inside and you allow for whatever OpenVPN port to the server, than this should be allowed. I would 1st match the  fwpolicy and  disable any ssl-inspection profile.

 

Typically OpenVPN uses udp or tcp 1194 but that port and protocol for tunnel/tap can be changed.

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rswinney99
New Contributor II

Additionally, If you are using the application control profile make sure you are not blocking the proxy category.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors