Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

SSL VPN: no matching policy

Hello, I have an issue affecting randomly our SSL VPN users. The users are LDAP users. Sometimes they can login, sometimes not and sometimes after several attempts. Looking at the event log, I did notice that the reason was " no matching policy" . I thought it could be a bad password, so I went to my domain controller and tried to find a similar event for one of the users. But did not find anything. This means that the Fortigate did not even connect to the DC to ask authorization while when the user can connect successfully, I do see an event on the DC coming from the Fortigate. Fotigate version is v4.0,build0272,100331 (MR2). We also require Client certificate on top of LDAP username and password. Error: Log Number 3 Last Activity 2010-10-26 08:44:44 Level alert Subtype sslvpn-user Action ssl-login-fail Message SSL user failed to logged in User david.portal Cluster ID FG600B3909600928_CID Log ID 39426 Timestamp 2010-10-26 08:44:44 VDom root Device ID FG600B3909600928 Reason no_matching_policy Tunnel ID 0 Tunnel Type ssl-web Remote IP 81.43.116.213 Tunnel IP 0.0.0.0 Sent 0 B Received 0 B Thanks for your help
2 REPLIES 2
patnor
New Contributor

Hi slimo, some time ago that you posted this message. Did you manage to fix this issue ? If yes, how ? I' m asking you, because I face the same issue. However, I am never able to login and *always* see the event " no_matching_policy" . Kind regards, Patrick.
patnor
New Contributor

Hi slimo, have been working on this issue. Found out that my FortiGate (ssl vdom) was not able to perform DNS lookup to the remote authentication server. After name resolving was fixed, the configuration was working fine ! Kind regards, Patrick.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors