Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

SSL VPN Portal not available

Hi All I' m a bit stumped here. I' ve been playing the our FortiWiFi 60A it get SSL VPN working. I have configured it for Web-only access as per the ' Fortinet SSL VPN User Guide' , but for some reason when I try and connect externally I get ' Page cannot be displayed' . I am accessing the IP configured on WAN1 with the URL of https://FortinetIP:10433/remote. I have checked the port number and all the group and policy stuff, but I thought I would at least get to the portal. The one thing that I do keep seeing is the comment ' Select interface that accepts connections from remote users.' I am only assuming that WAN1 is enabled for remote users as I can' t find any specify setting to enable this. Help would be much apprecitated. Thanks Ali
8 REPLIES 8
rwpatterson
Valued Contributor III

Try the address without the ' /remote' at the end.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

No Joy I' m afraid. The FortiWiFi is currently Nating our internal to its external IP if that makes any difference?? Thanks Ali
rwpatterson
Valued Contributor III

NAT-ting internal to external?? Bob is confused. . . :-/ From outside my network, once I put in my https://fortigate:10443/remote, I get the certificate verification screen (from Firefox). So I know we' re getting different results. Are you also sure that under ' VPN > SSL' that the SSL VPN option is enabled, and the port is correct?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Sorry for the confusion, I simily meant that the Fortinet is inline and running NAT for our internal network and not in transparent mode if this has any relivance? The Enable SSL-VPN is definately selected. Thanks Ali
rwpatterson
Valued Contributor III

You must also create a user(s), put him(them) into a user group, configuring the user group for SSL VPN with associated parameters. Then you need to create a policy for that user group, selecting ' SSL VPN' instead of ' accept' as the action. This policy should be at or near the top of the list, as should all encrypt or SSL-VPN policies. Once all this has been done, you should be met with success.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Hi Bob, this is what I' ve done :( The policy is the only policy in that zone so I am assuming it can' t be any higher. It has ID 5 and I tried moving it to 1 when I got the message you can' t move between zones. Bit stumped. Cheers Ali
rwpatterson
Valued Contributor III

By any chance do you have a virtual IP set up from the same IP address (as the Fortigate)? If port forwarding is not enabled, all the traffic will be passed to the other server, and the Fortigate will not be listening for SSL VPN logins.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Just another quick note to add to your troubleshooting.... Make sure you are forwarding port 10433 from any router that may be in front of the Fortigate.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors