hello there,
please help.
we using FG30E with firmware 5.6.12
we have created vpn ssl with tunnel mode, and client can connect successful.
we have create 3 policies (as shown video tutorial):
- WAN to VPN SSL, I don't think this have problem, since client can connect to vpn ssl.
- VPN SSL to LAN, I assume this has no problem, since client can access LAN after connect vpn ssl.
- VPN SLL to WAN, with configuration:
source: all IP, list of users vpn
destination: all
service: all
NAT: ON
AV: ON
accept connection.
fortigate restarting. client connect to vpn ssl, success.
but client can't access internet (trying browsing any website).
need help please. thank you
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
you shouldn't allow wan to vpn. This is creating security whoes and you do not really need it.
for internet you need vpn to wan so that's ok. Does the client have a default route to your FGT over the vpn?
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
you shouldn't allow wan to vpn. This is creating security whoes and you do not really need it.
for internet you need vpn to wan so that's ok. Does the client have a default route to your FGT over the vpn?
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
hello.
noted. wan to ssl already deleted.
thanks
Does the client have a default route to your FGT over the vpn --> do we need to create static route for this?
source : all, gateway: gateway FG (internet), interface ssl root?
Not on the FGT. The Route must be clientside.
Since we don't use SSL VPN I can't say much about how to push routes with it.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
noted. will check. thanks
No Internet means cannot access a web page? I asking in case there is DNS or other issue
Depending on the mode of the VPN you will NOT have a default gateway on the client.
A great tool for this is the built in packet sniffer. Log into the web UI or via SSH and type exactly this:
diagnose sniffer packet any 'host 10.10.10.10 and port 443' 4
Obviously replace 10.10.10.10 with the IP that your SSLVPN client has when connected. Either break down the packets or paste them into a txt file and post them back
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1517 | |
1018 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.