Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
airprakken
New Contributor

Testing SSL VPN from inside?

Sorry if this is silly but I find no references in the forums or docs or KB. I am configuring a simple, browser-only SSL VPN and attempting to test it from inside the network the FG is securing. I worked on this a number of hours, testing from inside the secured network, but always get Error:Permission denied when I attempt to log in to the VPN. Then I finally decided to go to town and access the Internet from another place -- and the VPN works fine! I must be missing some firewall rule or that there is something else preventing this. I would really prefer to sit here in my office rather than at Starbucks to do this work. Summary: FG50B running v4.0.2,build0099,090407 3 VLAN' s inside, one of which is where I want to go with the VPN from the outside. Using a PC on any of the 3 VLAN' s, including one which is routed ONLY to the Internet, I always am prevented from logging in to the VPN. I use the appropriate port on the outside static IP of the FG device and get clear through to the login screen before being denied at login. If I go somewhere else and access the Internet doing EXACTLY the same thing to the same IP address (I just refresh the same browser window on the same netbook with a new connection), I can log in, so the basic config is fine. Thanks for any help. Randy in Oregon
4 REPLIES 4
rwpatterson
Valued Contributor III

Welcome to the forums Randy. By design, you cannot connect to the SSL VPN from the inside. You' re already on the inside, so the connection fails. Best bet is to grab some wireless from the air, or get a separate cable connection for testing. Sorry I couldn' t give you better news...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Create a SSLVPN policy from the " inside" interface to itself. --Ali
rwpatterson
Valued Contributor III

ORIGINAL: ayazdi Create a SSLVPN policy from the " inside" interface to itself. --Ali
Never too old to learn something new... ;)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
airprakken
New Contributor

That works fine Ali -- thanks
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors