Hi,
I have created a remote IPsec VPN for remote users. the users can connect to the VPN.
However, they can't access anything in the LAN behind the FortiGate through HTTP or HTTPS.
For example, I can SSH to the FortiGate to manage it; however, I can't access it through HTTP/HTTPS.
I don't have a route issue because I have ping/ssh to the FortiGate/LAN behind it. I don't have a Policy issue as I have allowed all the services.
Model: 401F
Version: v7.6.4.
I have disabled all security profiles on the rule, set the certificate inspection to 'no-inspection', and all services are allowed.
Please share the following:
Where portX is the port connected to your internal services to which you want to access (you can hide the IP).
Please see the output of the requested command in the image below.
Nothing abnormal so far.
Can you check if you have VIPs and policy routes?
I don't have policy routes configured, but I have VIPs configured; however, none of them are configured on the ports that are used by IPsec.
And I have other customers with VIPs, we are not facing any issues with them (same setup).
The "diag debug flow" output you shared doesn't contain the first lines.
I mean can you share what is before this line:
2025-11-10 12:20:38 id=65308 trace_id=672 func=__iprope_check_one_policy line=2190 msg="checked gnum-10000f policy-4294967295, ret-no-match, act-accept"
| User | Count |
|---|---|
| 2822 | |
| 1431 | |
| 812 | |
| 786 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.