Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Yayat1
New Contributor

SSL VPN

can not reach by ping to hostname over SSL VPN

4 REPLIES 4
Potato168
New Contributor II

What is the DNS you setup for SSLVPN client?
And, does your SSLVPN profile allow routes to the DNS?

Also, Have you setup Policy to allow SSLVPN to the DNS?

Yayat1
New Contributor

- for SSL VPN i was setup my local DNS server

- already allowed coz if i pinging to my local network using IP address already reply

- policy direct to DNS IP Server ?

smaruvala
Staff
Staff

Hi,

 

- Are you trying to ping a hostname in Internet or a hostname which inside your network?

- When you try to ping the FQDN does it resolve to an IP address or it does not even resolve?

- If it resolves and you are observing timeout in pings then you can verify if the firewall has the correct policy and route for the communication.

- If the IP is not resolving then try to ping the DNS server from the client PC and check the reachability. You will need to have policy to allow the DNS communication from SSL VPN interface to the destination interface. 

 

Regards,

Shiva

jera
Staff
Staff

Hello @Yayat1 

 

1. Have you enabled split dns?

2. When you connect to SSLVPN, can you run nslookup to your internal domain and share the result?

JE
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors