Created on 05-20-2010 12:22 AM
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
ORIGINAL: darrencarr Hi Bill, If your DMZ is connected to your Fortigate then you don' t need to define the route. If you go into the system and go to Router -> Monitor you should see the ntry for your DMZ. The type should be ' Connected' [size=3]Yes, " Connected" shown[/size] If this is the case then all you should require is a policy from ssl.root -> DMZ. You can further restrict the policy by defining the source as the SSLVPN range and also the destination host(s). [size=3]Yes, there is policy " ssl.root ->DMZ" [/size] With this in place it should work. If this fails you can look into setting up a debug session on the firewall to better understand the flow of the traffic, and where the problem lies. To do this (please bear with me I am using FortiOS 4) use the following steps: dia deb flow filter sa <ip address of your ssl.root connected host> dia deb flow filter da <ip address of the host you are trying to connect to in the DMZ) dia deb flow show console enable (enables debugging to the console) dia deb flow trace start 99 (outputs the first 99 lines of the debug session) dia deb en (enables the debug) [size=3]Could this be done in the CLI console? I did enabling the debug, but what I do? I ask the remote SSL VPN user to try accessing the DMZ and then what should I get? How and where to review the debug session?[/size] After doing this attempt to connect to the DMZ via the ssl.root, and review the results of the debug session. You will more than likely find it is a policy issue or something along these lines. You may even have a static route in your firewall that is causing the traffic to be routed to the wrong destination. Given your network is connected to the firewall (DMZ) and has a distance/metric of 0, it should superceed any static route you have defined. If you are still struggling post the output of your debug session. D[size=3]thanks so much for your help[/size]
Created on 05-25-2010 12:53 AM
ORIGINAL: darrencarr Hi Bill, You can use PuTTY client to capture the debug log. Download the client from http://www.putty.org/ and adjust the window properties to capture 200 lines of output. Get the debug setup just before the user connects. If you do it too soon (depending on your timeout settings) your session may expire. I have PuTTY ready, but which IP should I key in " dia deb flow filter sa" before the SSL VPN user connects? As the SSL VPN user will get their IP after they are connected. I tried a SSL VPN user connected IP 192.168.117.100 to dia deb flow filter sa, and ask the user to access http://172.17.100.1, but the putty dont show anything. Do I need to look into other log file for the debug? Can you also tell me what model of Fortigate you are using, and how your network is laid out, i.e. are all the Interfaces (DMZ, Internal) interfaces on the Fortigate unit? Can you also detail each of the interfaces, their IP address and subnet mask. Reason I ask is that I have seen people use an IP address for an interface of 172.17.7.1/32 I' m using Fortigate-60 3.00-b0741(MR7 Patch 5), all interface are on the Fortigate. Network layout: dmz 172.17.100.254 / 255.255.255.0 internal 192.168.116.1 / 255.255.255.0 wan1 (PCCW) 202.181.x.x / 255.255.255.224 Really, if your interfaces are configured correctly, and are all configured on the Fortigate, then all you need is policies that are correctly configured. Post the debug log and we can take it from there
dia deb flow filter sa <ip address of your ssl.root connected host> dia deb flow filter da <ip address of the host you are trying to connect to in the DMZ) dia deb flow show console enable (enables debugging to the console) dia deb flow trace start 99 (outputs the first 99 lines of the debug session) dia deb en
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
753 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.