Long time reader, first time poster....Have a head scratcher here....
Have a multi site customer running ADVPN. ADVPN is established and I have my rules built. However, access to one of the subnets at the HUB site is not reachable, I can reach all over subnets at the hub site. I verified my routing is in place, and all my other spokes can reach this just fine. After I verified I didn't have any routing issues, I turned to policies. First I checked my HUB sute to make sure I didn't need to add an address object to the inbound ADVPN rule, nope, good there (It's set to All) SO I moved to my branch site.
My spoke rule is:
Source: Internal Zone
Dest: ADVPN HUB
Originating: Internal Group (has all my internal subnets)
Dest: All
Services: All
NAT: Disabled
I do have a recursive rule as well.
when I do a policy lookup from any of my internal VLANs to 192.168.1.4 I get:
"Policy lookup matches the implicit deny policy. No explicit policy exists from source interface "Int-Wire-104" to destination interface "ADVPN HUB" as determined by a route lookup to "192.168.1.4"
Int-Wire-104 is part of my internal zone
if I change it to 10.5.24.1 which is my Core switch at the hub location it hits the rule referenced above.
I tried deleting and rebuilding my rules as well just to rule out a fortibug we run into with SSLVPN rules from time to time where we have to delete and rebuild them for them to work....
Firmware is 5.4.4
Model is a 200E
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1633 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.