I would really like to get a remote access VPN to my Fortigate network which is connected via Starlink, has anyone been able to make this work?
I have a Fortigate 60F running version 7.2.11
Supposedly Starlink CG-NAT network supports SSL VPN (I have read it does not support IPSEC VPN) but I have no luck. I have not found an option for "NAT Traversal" in the Fortigate SSL VPN config anywhere.
I have done a packet sniffing session on the WAN interface of the Fortigate and it shows no traffic coming from my public IP while trying to ping or connect via SSL VPN. I have confirmed with support that my SSL VPN config is correct and I am successfully using identical config at sites with Comcast internet connection.
Hi Team,
To set up a remote access SSL VPN to a FortiGate behind Starlink, follow these steps:
1. Ensure that your SSL VPN configuration on the FortiGate is correct. Since you mentioned it works with Comcast, the configuration should be similar.
2. While SSL VPN does not have a specific "NAT Traversal" option like IPsec, ensure that your FortiGate is configured to handle connections behind NAT. This is typically managed automatically by SSL VPN.
3. Confirm that Starlink allows SSL VPN traffic. Some users have reported issues with certain ports being blocked. Ensure that the port used for SSL VPN (e.g., 10443) is open.
4. Packet Sniffing:
- Since you are not seeing traffic on the WAN interface, ensure that the correct public IP and port are being used in the client configuration.
- Double-check the firewall policies to ensure they allow SSL VPN traffic.
5. **Test Connectivity:**
- Use a different network to test the SSL VPN connection to rule out any client-side issues.
- If possible, test with a different ISP to confirm that the issue is specific to Starlink.
6. Check with Starlink to confirm if there are any known issues or additional configurations required for SSL VPN.
Please do follow the below article:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-tunnel-with-FortiGate-using-Starlink...
Note: As in the latest version, SSL VPN is not supported so you have to configure the IPsec dial-up VPN.
Regards,
Durga A
1: Done
2: If it is handled automatically, are there any settings that would break this?
3: I opened a ticket with Starlink and they just said that they support SSL VPN and we should ensure "NAT Traversal" is enabled. I have also tried port 443 in my SSL VPN settings on the Fortigate and client settings with no luck
4: Done. I have the same rules in place which allow the SSL VPN to work in sites with Comcast
5: Done
6: See 3
Still no luck. We currently do not have a Fortigate installed at our office to try the Site-to-Site option, but I have been advocating for that and will try when I can. Assuming the local Fortigate would need to have a public IP for double NAT reasons so I cannot do it from my test bench.
To confirm, 7.2.11 still supports SSL VPN?
Thanks for your reply
Should work for 60F/7.2.11. I was using SSL VPN with 40F/7.2.11 before upgrading it to 7.4.7. Still work now.
Toshi
User | Count |
---|---|
2571 | |
1365 | |
796 | |
653 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.