I have a strange issue.
- Two locations (on different continent) connected via ipsec-vpn.
- Both sites have FGT60D os 6.0.3
- The tunnelinterface have assigned IP-address (Local/Remote) with subnet 255.255.255.255-mask
- The remote site have some policybased routing since some internet-traffic must be routed via internet-connection on HQ.
Everything works fine; both site2site-traffic, and traffic from remote site via HQ to internet. The performence is as expected.
But the FGT-webUI will not load from remote site via the ipsec; the certifcate warning occour as normal but after that nothing is happening. I have tried different browser (Chrome, Edge etc) with same result. I have done some "diag sniffer packet"-sniffing and the packet seems to be routed correctly. When I do rdp-to a comuter on remote site I am able to connect the webUI on the same IP as I failed connect to from the other end. This is the same in both direction; both from remote site to FGT@HQ and from HQ to FGT@remote.
SSH to the Fortigate is working normal over ipsec.
Where could I start digging?
Y
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Sounds like no routing issues. And assuming there is no "trusthost" issue either allowing all or both subnets.
Then it must be https level. I would enable http temporarily to see any difference. Then start running wireshark to compare packets between local access (success) and remote access over IPsec (failure) to see where/when it breaks down. If client side is waiting for something that it can't get from the FGT, you might need to run packet capture on the FGT side either via GUI or CLI then convert to pcap.
Thanks;
http gives no issues, so my guess is also that it is on https-level. I will follow you suggestion but concider to start with re-issuing the ssl-certifcates.
Best regards
Yngve
What versions of TLSv1.x are your allowing? Can you test with curl against the remote-site?
curl.exe -v -k https://x.x.x.x
Do you get the certificate and successful TLS handshake?
Ken Felix
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.