Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jon_Fleming
New Contributor

Netmask preventing SSL VPN tunnel from working?

Fortigate 50B 3.00-b0726(MR7). Since there are sometimes issues with my IPSec VPN, I thought I' d try out an SSL VPN. I set it up per the documentation: a user group that is authenticated by my LDAP server, an " SSL Internal network" address of 192.168.0.0/255.255.255.0, a tunnel IP range of 192.168.0.8-192.168.0.49 which is outside my DHCP server' s range, and a firewall policy from WAN1/any to internal/" SSL Internal network" always/any/SSL VPN and the LDAP user group allowed. I can connect using IE7 as advertised and activate the tunnel and get an IP and DNS server and WINS server and whatnot EXCEPT ... The fortissl adapter gets a subnet mask of 255.255.255.255. So even though I have a 192.168.0.8 IP I can' t connect to anything on the internal network. If I try " Test for Reachability (ping)" in IE to 192.168.0.250, a popup advises me that it' s reachable. If I ping 192.168.0.250 at the command line, I get four timeouts. What have I missed?
36 REPLIES 36
rwpatterson
Valued Contributor III

Jon, check your gmail.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Jon_Fleming

Thanks to Bob' s excellent help, I' m up and running. Bob, now split tunneling is working even though I made no changes to the configuration. In the next few days I' ll try to summarize my setup and post it here for others.
rwpatterson
Valued Contributor III

Great news. Thanks for the follow up.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

What did you end up changing to make it work? I have everything working on the SSL VPN except split tunneling. I can access the remote resources and everything but I dont want remote users using bandwidth when they have their own to waste. Thanks!
Jon_Fleming
New Contributor

Yes Ive read that. When I tried to enable the split tunneling at the end, it gives me that error about bad destination in the split policy
Jon_Fleming
New Contributor

I finally realized that it' s complaining about the firewall policy. You can' t enable split tunneling until there' s a policy that defines what to split. In my example, I think that' s the ssl.root -> internal policy. So set everything up without split tunneling and enable split tunneling as the very last step.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors