I Have a problem with accessing to local ressource from SSL VPN (Tunnel & Web).
We use a Virtual IP, to NAT our Public IP to FG Wan interface (for SSL VPN Portal and Tunnel Mode), we have create a policy for this NAT, and its Work fine, and after we have configure the VPN SSL , and create a policy match the VPN SSL Traffic, we can connect with VPN SSL Portal, and FortiClient (Tunnel mode), but we cannot pinging or accessing to the local ressouce on DMZ.
When we make a diagnose, we can see the original direction and reply direction .
You can find attached the VPL SSL Architecture.
Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You must be mis-discribing your arrangement. The VIP or DNAT for TCP 443 or 10443 or whatever you have SSL-VPN config has to be configured at the router, which has 194.x.x.x, instead of the FGT. Otherewise SSL VPN traffic never hit the FGT, of which outside IP is 192.168.1.2 (private IP).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.