this is Payam and this is my first post here :)
we have an issue and this is about SSL VPN and Virtual IPs
when we connect to our network with SSL VPN we can not access Objects with their Virtual IP but that object is accessible with its local IP address.
there is no same zone between SSL VPN interface and the interface that we use to access the object
also the rule is from our source , from SSL VPN interface to All with service All
can anyone help to solve this issue ?
Then, does the route exist back from the objects toward the SSL VPN client IPs? Also if it's split tunnel, is the objects' subnet specified in the portal config as well as the other subnets they need to reach?
I think the problem is extintf/extip of your VIP is bound to the external interface facing the internet. SSL VPN is coming past that interface and terminated inside. So can't access the outside of the external interface. The same thing would happen when you try accessing outside interface of VIP from a local device connected to internal interface.
Why don't you use the local IP of the servers to access them via SSL VPN? That's the whole purpose of SSL VPN. VIP is for the access coming from Internet without a VPN.
I have the same problem. Is this possible to set up with Fortigate?
Also, this is not true:
"The same thing would happen when you try accessing outside interface of VIP from a local device connected to the internal interface." - You can configure a rule for this, and it will work fine. However, I can not set the same firewall rule for SSL-VPN - why not?
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.