Hi All,
I have two issues currently 1) I'm trying to setup a IPSEC VPN for remote users using forticlient, but for some reason when I try to connect, get the error message to check configuration pre share key etc.
But if I am connected directly to the network, it works.
When trying to connect through wifi at any location it seems to be trying and during pinging I notice that I lose internet connection.
2)Also I noticed that I can't access the fortigate using HTTPS, on any location for remote management or even connected to the network, I can acces through the internal IP only.
Is there something I need to enable?
thank you in advance
Hi,
"1) I'm trying to setup a IPSEC VPN for remote users using forticlient, but for some reason when I try to connect, get the error message to check configuration pre share key etc."
To further assist, you need to capture the packets from the below command when you try to connect IPSec VPN
diag debug reset
diag debug appl ike -1
diag debug enable
After initiating the above commands on the ssh session then try to connect the VPN from outside.
"When trying to connect through wifi at any location it seems to be trying and during pinging I notice that I lose internet connection."
> do you mean after VPN is connected, are you trying to ping the internal resource, then the internet connection is lost, if yes you need to enable the split tunnel in order to route only the interesting traffic via the tunnel, or route all the traffic via the tunnel and create a firewall policy from VPN interface to internet interface to allow the internet traffic from VPN client.
2)Also I noticed that I can't access the fortigate using HTTPS, on any location for remote management or even connected to the network, I can acces through the internal IP only.
Is there something I need to enable?
>> please make sure to enable HTTPS option under System > Network > Interfaces > edit the WAN1 interface
Do let us know if you have any queries.
Regards,
Somu
One should mention that you should not enable HTTPS or SSH on any internet facing ports per default. It's OK for a limited time while debugging the VPN but anything beyond that is asking for trouble. Be sure you give the admin account a secure password.
Hi Somu and Ede,
Thank you for both your replies.
I manage to find the issue on why I can't connect.
I called a fried of mine who work at ISP, which provides me internet and seems that my adsl router is a residential router and they don't give public ip to them only to business router.
But when I'm connected physically to my firewall the vpn connection works.
As for the connecting to the https issue, I have enabled it at a client, but not working, should SSH also be enabled?
And I need to check with their ISP if they have public ip also.
Krs,
Vernon76
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.