Specs: 300c / 5.2.1 GA 618 // have 4 different ssl vpn portals running for over a year.
My policy rule set:
From To Source Destination
ssl.root ssl.root All / (ITAdmin group) Group of IT Admin subnets --- under VPN - ITAdmin portal I have listed the IT Admin subnet group for "routes"
My issues is this, from reading the FGT Cookbook for setting up ssl vpn's when 5.2.1 was released I used 'ssl.root for my 'From & To" interfaces as per my understanding of the document. VPN's worked excellent for over a year and then I would receive reports of staff not able to reach applications that worked in the past. Spoke to FGT and was informed that instead of using 'ssl.root for the 'To" source interface but to use the VLANs that were created. So I dropped ssl.root and replace the vlans, but then I noticed I could not access other items. After doing FGT packet sniff's and packet debugs and seeing nothing wrong with the configuration or dropped packets, I decided to drop all of the VLANs on the interface and replace them with 'ssl.root'. once I did this all of the items I could not access I could again. I receive a different answer everything I speak with FGT. I am perflexed,,,,,,,anyone else experiencing similar issues?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi !
To be honest - I'm not sure what do you mean - "I receive a different answer everything I speak with FGT" ?
ssl.root to ssl.root policy seems to me like useless loopback - can you give me link to that cookbook ?
ssl.root to internal vlans is OK and it's obvious to me.
Dominik Weglarz, IT System Engineer
When I called to speak with the FGT tech support I have received two different answers.
I've been told to use ssl.root for incoming & outgoing interface.
I've been told to use ssl.root for incoming and for outgoing interfaces (internal) use my vlans.
My issue that i was currently facing was resolved when I switched back my internal interface to use ssl.root.
I've attached a screen picture of my config.
I was able to resolve this by completely removing the vpn / portal & re-creating it. using ssl.root for the srcint & the vlans for the dstint.
Thanks for the help.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1633 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.