Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dabanjm
New Contributor II

Remote IPsec user can't access HTTP/HTTPS

Hi,

I have created a remote IPsec VPN for remote users. the users can connect to the VPN.

However, they can't access anything in the LAN behind the FortiGate through HTTP or HTTPS.

For example, I can SSH to the FortiGate to manage it; however, I can't access it through HTTP/HTTPS.

I don't have a route issue because I have ping/ssh to the FortiGate/LAN behind it. I don't have a Policy issue as I have allowed all the services.

Model: 401F

Version: v7.6.4.

DJM
DJM
15 REPLIES 15
dabanjm
New Contributor II

I have disabled all security profiles on the rule, set the certificate inspection to 'no-inspection', and all services are allowed.

DJM
DJM
AEK
SuperUser
SuperUser

Please share the following:

  • show firewall local-in-policy   (from CLI)
  • show system interface portX

Where portX is the port connected to your internal services to which you want to access (you can hide the IP).

AEK
AEK
dabanjm
New Contributor II

Please see the output of the requested command in the image below.

2025-11-12 09_47_54-FortiGate - MHO-FGT-01 — Mozilla Firefox.png

DJM
DJM
AEK

Nothing abnormal so far.

Can you check if you have VIPs and policy routes?

AEK
AEK
dabanjm
New Contributor II

I don't have policy routes configured, but I have VIPs configured; however, none of them are configured on the ports that are used by IPsec.

And I have other customers with VIPs, we are not facing any issues with them (same setup).

DJM
DJM
AEK
SuperUser
SuperUser

The "diag debug flow" output you shared doesn't contain the first lines.

I mean can you share what is before this line:

2025-11-10 12:20:38 id=65308 trace_id=672 func=__iprope_check_one_policy line=2190 msg="checked gnum-10000f policy-4294967295, ret-no-match, act-accept"
AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors