Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kssupport
New Contributor

Internet access for VPN SSL CLIENT

hello there,

please help.

we using FG30E with firmware 5.6.12

we have created vpn ssl with tunnel mode, and client can connect successful.

we have create 3 policies (as shown video tutorial):

- WAN to VPN SSL, I don't think this have problem, since client can connect to vpn ssl.

- VPN SSL to LAN, I assume this has no problem, since client can access LAN after connect vpn ssl.

- VPN SLL to WAN, with configuration:

source: all IP, list of users vpn

destination: all

service: all

NAT: ON

AV: ON

accept connection.

 

fortigate restarting. client connect to vpn ssl, success.

but client can't access internet (trying browsing any website).

 

need help please. thank you

1 Solution
sw2090
Honored Contributor

you shouldn't allow wan to vpn. This is creating security whoes and you do not really need it.

for internet you need vpn to wan so that's ok. Does the client have a default route to your FGT over the vpn?

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

View solution in original post

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
5 REPLIES 5
sw2090
Honored Contributor

you shouldn't allow wan to vpn. This is creating security whoes and you do not really need it.

for internet you need vpn to wan so that's ok. Does the client have a default route to your FGT over the vpn?

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
kssupport

hello.

 

noted. wan to ssl already deleted.

thanks

 

Does the client have a default route to your FGT over the vpn --> do we need to create static route for this?

source : all, gateway: gateway FG (internet), interface ssl root?

 

sw2090
Honored Contributor

Not on the FGT. The Route must be clientside.

Since we don't use SSL VPN I can't say much about how to push routes with it.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
kssupport

noted. will check. thanks

 

fcb

No Internet means cannot access a web page? I asking in case there is DNS or other issue

 

Depending on the mode of the VPN you will NOT have a default gateway on the client.

 

A great tool for this is the built in packet sniffer. Log into the web UI or via SSH and type exactly this:

 

diagnose sniffer packet any 'host 10.10.10.10 and port 443' 4

 

Obviously replace 10.10.10.10 with the IP that your SSLVPN client has when connected. Either break down the packets or paste them into a txt file and post them back

Labels
Top Kudoed Authors