Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sid_dawg
New Contributor

Puzzled SSL-VPN Interface Behavior

Specs: 300c / 5.2.1 GA 618 // have 4 different ssl vpn portals running for over a year. 

 

My policy rule set:

From           To            Source                                  Destination

ssl.root        ssl.root      All / (ITAdmin group)            Group of IT Admin subnets  --- under VPN - ITAdmin portal I have listed the IT Admin subnet group for "routes"

 

My issues is this, from reading the FGT Cookbook for setting up ssl vpn's when 5.2.1 was released I used 'ssl.root for my 'From & To" interfaces as per my understanding of the document. VPN's worked excellent for over a year and then I would receive reports of staff not able to reach applications that worked in the past. Spoke to FGT and was informed that instead of using 'ssl.root for the 'To" source interface but to use the VLANs that were created. So I dropped ssl.root and replace the vlans, but then I noticed I could not access other items.  After doing FGT packet sniff's and packet debugs and seeing nothing wrong with the configuration or dropped packets, I decided to drop all of the VLANs on the interface and replace them with 'ssl.root'.  once I did this all of the items I could not access I could again. I receive a different answer everything I speak with FGT.  I am perflexed,,,,,,,anyone else experiencing similar issues?  

sidney yoder
sidney yoder
3 REPLIES 3
dominikw
New Contributor II

Hi !

To be honest - I'm not sure what do you mean - "I receive a different answer everything I speak with FGT" ?

ssl.root to ssl.root policy seems to me like useless loopback - can you give me link to that cookbook ?

 

ssl.root to internal vlans is OK and it's obvious to me.

Dominik Weglarz, IT System Engineer

Dominik Weglarz, IT System Engineer
sid_dawg

When I called to speak with the FGT tech support I have received two different answers.

I've been told to use ssl.root for incoming & outgoing interface.

I've been told to use ssl.root for incoming and for outgoing interfaces (internal) use my vlans. 

 

My issue that i was currently facing was resolved when I switched back my internal interface to use ssl.root. 

I've attached a screen picture of my config. 

sidney yoder
sidney yoder
sid_dawg

I was able to resolve this by completely removing the vpn / portal & re-creating it. using ssl.root for the srcint & the vlans for the dstint.

 

Thanks for the help.

sidney yoder
sidney yoder
Top Kudoed Authors