Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tech-OFM
New Contributor

Web SSL to Fortinet no longer working after upgrade to 7.2.6

Background:  We use the WEB SSL VPN portal to provide remote access to the firewall for management.

Reason:  This allows us to put the Admin page behind the SSL VPN but does not require a full tunnel to use.  This way you can work on several firewalls at once.  Multiple customers.

 

We are noticing that as we deploy 7.2.6 as an upgrade to 7.2.5 that our login works but the firewall Policies screen and the Interfaces screens, among others, do not load completely.  Reloading the page shows an empty list.

 

I have tried several browsers, Mac and Windows.  Chrome, Edge, and Firefox all do it.  Cache has been cleared.

 

Anyone run into this, and if so do you have a workaround?  I am sure it will be resolved eventually.

 

Steve

3 REPLIES 3
mauromarme
Staff
Staff

Hello Steve,

I hope you're doing well.

I wanted to draw your attention to a potential challenge with SSL VPN Web Mode when it comes to handling modern websites. The newest websites frequently depend on dynamic languages, which can occasionally introduce complications with the redirection process, ultimately leading to incomplete content display.

Considering my experience, I'd recommend exploring alternatives to SSL VPN Web Mode. One potential option is to utilize the ZTNA Access Proxy on FortiGate. The advantage of this approach is that it doesn't require a VPN connection. It is just a proxy connection allowed based on clients ZTNA TAGs.

Regards,

 

Mauricio Marin
Fortinet TAC Senior Engineer
Tech-OFM

Thank you Mauricio for the response.

 

Is there a way to use a single ZTNA (client) installation with multiple customers?  Each of these people may or may not have a EMS server up and running.  I certainly can't hijack the EMS/ZTNA settings for my own personal use.

 

The only other way I can think to do it would be an authentication page which stops the user first, then redirects to the actual Admin pages.  Given the authentication vulnerabilities in the last two years, it is not a good idea to put this Admin interface on the internet directly.

 

Any other ideas?

mauromarme

Hello Steve,
You can have one EMS on your side and multiples FortiGates connected to it.
With that, the ZTNA Client only need to be connected to your EMS and would get access to whatever resource you allow access to. 

That's the only thing that comes to my mind. 

Mauricio Marin
Fortinet TAC Senior Engineer
Labels
Top Kudoed Authors