Hi ,
we have three office site A B & C with 3 FG80c.
There are ipsec vpn beetween A-B A-C B-C (Internal from A can communicate with B and C resource; ....).
Theres are 3 sslVPN for each site for external communication.
My issue : none of VPNSSL connections lets vpn SSL users to access to other site after a successfull connection.
example : when i'm connected from external by sslvpn to site A, i can't see any resource of site B or site C. Is that a policy probleme (i checked all sslroot to ipsep interface seemed ok...in each fortigate)?
thanks a lot.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Have you check the following settings :
- Is the VPN SSL subnet is allowed in the ipsec phase 2 ? - have you created a static route in the FortiGate in site B and Site C ?
Regards
More importantly did you run diag debug flow , with one of the sslvpn_pool address given to an external user ?
That and above will at least give you a running start as to what to look at.
PCNSE
NSE
StrongSwan
ok i'll try this.
thanks
FWIW & in your setup , you would be wise to explore ospf-over IPSEC for the A_B_C spokes. You would only need to advertise the SSLVPN pool address into the OSPF domain and ensure fw-policies to allow the clients access to the correct services.
Ken
PCNSE
NSE
StrongSwan
Hi, finaly there was missing vpn policy rules for wan->eachOffice
thanks
Yes : there are 0.0.0.0 for all phase 2
and static route On B and C are there for Both "internal" A and "SSLVPN adresses" A
Yeah, same problem, someone can help please ?
Hello, my issue was resolved, i've missed a policy rule.
set srcintf "wan1" set dstintf "destination" set srcaddr "all" set dstaddr "destinationAdress" "destinationAdress-VPN-SSL" set action ssl-vpn set identity-based enable config identity-based-policy edit 1 set schedule "always" set groups "ssl users" "SSL portal ext" set service "ALL" set sslvpn-portal "full-access" next end next
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1731 | |
1099 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.