Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Rakeshi_
New Contributor II

VPN

Hi Everyone. VPN to VPN IP is not pingable, we use forticlient as vpn. We tested to create an inbound and outbound policy in fortigate(VPN to WAN, WAN to VPN), but doesn't resolve the issue. Can someone guide me how to solve this issue? Looking forward from your responses, thanks.

4 REPLIES 4
ozkanaltas
Valued Contributor III

Hi @Rakeshi_ ,

 

If you want to access another vpn client from a vpn client, you need to define a rule from ssl.vpn interface to ssl.vpn interface.

 

Also, you can review this article for your request.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Communication-between-two-or-more-SSL-clie...

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Umer221
Staff
Staff

@Rakeshi_ 

 

If you are looking to allow traffic between remote users (connected via FortiClient) and another site connected via IPSec tunnel, then here is an article to give you an idea on how the traffic flows:
https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/45836/ssl-vpn-to-ipsec-vpn

 

 

Additionally, you can try changing the configuration using the above article if there is a slight difference in the topology between the connected resources.

 

If you have found a solution, please like and accept it to make it easily accessible to others.

NSE 4-6-7

hbac
Staff
Staff

Hi @Rakeshi_,

 

Which IP are you trying to ping? Are you pinging from VPN client to an IP address behind the FortiGate? You can run debug flow to see if it is being dropped. Please refer to this article: https://community.fortinet.com/t5/Support-Forum/quot-Failed-create-SSL-quot-using-7-2-5-0847-Interim...

 

Regards, 

HiralShah
Staff
Staff

Hello @Rakeshi_ 

Can you please provide more information about IPs, and how they are connected, you can send us screenshot.

So we can understand which IP is not pinging 

You can run this command on FortiGate:

get router info routing-table details x.x.x.x---destination IP which you are trying to ping 

Make sure you have tunnel interface to that destination interface policy configured.

Hiral
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors