- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Split Tunnel issues : user cannot access a portion of subnet which should be accessible
Hello,
I have an odd problem. A user (and SSLVPN users generally) were able to access a network segment which they are no longer able to while using a split tunnel. All of a sudden, traffic appears to be timing out when trying to access certain addresses on a portion of the exported subnet that should be accessible.
Shown above in the 1st 4 are the configuration on the fortigate for the SSLVPN. shown below in the last 3 are the route table on the user's device, as well as the output of their ipconfig /all showing both their Forticlient virtual adapter, and their physical wifi adapter.
the user can ping 10.55.4.* addresses, but not 10.55.5.* addresses
Thank you,
Matt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Matt
Try enable all logs in the related policy and in implicit deny as well and see if the traffic toward 10.55.5.* is being blocked.
You may also check with sniffer command while trying to access 10.55.5.*:
diag sniffer packet any "host <IP>" 4
