Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tyrsofrage
New Contributor II

SSL vpn to vlan implicit deny

Ive been trying at this for awhile and cant wrap my head around the problem. 

 

Im trying to go from ssl vpn to vlan100

Fortigate sees vlan100 in the routing table.

 

It has a firewall policy allowing it. 

 

yet the policy match tool and debug shows it going to the implicit deny policy

 

 

What else am I missing?

1 Solution
pminarik
Staff
Staff

The policy demands an authenticated user - are they listed in the table of authed users?

 

> diag firewall auth list

=> find the username, check if it has the right IP

[ corrections always welcome ]

View solution in original post

3 REPLIES 3
tyrsofrage
New Contributor II

debug output

pminarik
Staff
Staff

The policy demands an authenticated user - are they listed in the table of authed users?

 

> diag firewall auth list

=> find the username, check if it has the right IP

[ corrections always welcome ]
tyrsofrage
New Contributor II

Thanks! That lead me down the right path. 

I ran that command and saw the right user listed but it said it was in a user group. The GUI didn't show that user in any group. I matched the group mentioned in the cli to the user in the GUI and it worked. Kinda odd.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors