Hi Guys,
I have 100D firewall the SSL VPN was working fine, But for Some reason I removed it and connected the other firewall 60D for few days, and kept 100D aside for few days without making any changes.
Now when I am trying to connect the 100D firewall the SSL VPN From Outside is Not working I am not able to Connect to the VPN with Forticlient it stops at 10% and I am getting Error " Unable to Establish the VPN Connection. The VPN server may be Unreachable" however I am able to browse the web Access from internal Network and I am able to login.
1)I have reinstalled and installed the Forticlient.
2) Not Made any Changes to VPN settings as I Said Earlier.
3)Note The Public IP is DHCP and it is changed.
4) I also tried to connect with Remote gateway IP which the Public IP of the Firewall and hostname still same issue it doesn't connect and stops at 10% and gives error.
Can anyone please help
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @eliaslatif ,
Can you access your ssl-vpn portal via browser from the internet?
If you say yes, it might be your FortiClient settings aren't correct. Sometimes FortiClient can't save customized port settings. Can you check that area?
Also, you say "public IP is DHCP and changed" What do you mean by that?
Hello Ozkan Thanks again for you quick response.
1) i am able to access the vpn web from internal network not from outside. https://10.39.1.13:10443
2) I have not made any changes as I removed the firewall and kept as it is the SSL VPN was working fine earlier.
3)the Public IP given by service provider is DHCP its Not Static If The Device is Rebooted the IP changes Everytime. But it should not be an issue because the device rebooted multiple times earlier and the SSL VPN was working fine without any issues.
any thing Related to policy ? Should I delete the VPN policy and create again ?
Any suggestions?
Bad Day For Me, Mistakenly Disabled LAN Interface and Now on the Other Firewall the VPN is Not Working.. 🥲
Created on 05-16-2024 05:16 AM Edited on 05-16-2024 05:16 AM
Hello @eliaslatif ,
As I understand, there is an ISP router(or modem) in front of FortiGate. Can you check this router configuration? If you want to access your FortiGate from outside you need to configure dnat on your ISP router. Maybe your FortiGate IP address has changed and you need to configure your isp router with this IP address.
I think your ssl-vpn configuration is correct. Because You say, I can access and login the ssl-vpn portal internally. That indicates everything works well.
Hello,
Running a sniffer on the FGT device might help see if indeed any packets are arriving at the FGT at all. If not, most likely the modem/router before the FGT might be dropping the packets and not allowing the VPN to get formed.
Also when you say from the "Outside" you mean externally fro the FGT itself so from the internet? In that case what IP are you using on your FCT to connect to?
The DHCP IP on the FGT or the public IP on the modem/router?
Ezupa,
Yes outside means from external network I am not able to access the VPN, Within the Fortigate Network I am able to Access the Web VPN and I am able to Login in to it . I am using the same (public ip address ISP IP) / xyzfortidyndns.com as remote gateway to connect from Forticlient. It was working absolutely fine.
It looks like other Fortigate firewall of ISP provider Might be dropping the packet. ill call the ISP shortly and aks them to check. thanks A lot
Thanks Ozkan and ezhupa, you guys are correct as I am working on it remotely, I just came to know that there is another Fortigate firewall of the ISP Provider which might be dropping the packet. Should I call them and tell them to enable Dnat On that Device as well ? Please suggest anything else which I need to ask them to check, so I can call them ask them to enable the settings accordingly.
Thanks in Advance.
Hello, were you able to resolve your issue? I am experiencing the same problem. The only difference is that I have a static IP
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.