Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pbrown134
New Contributor

routing to subnet behind sslvpn client

I have a partially working SSLVPN setup between 2 fortinets.
The tunnel itself comes up fine.
What I'd like to be able to do, is route packets from/through the main router, to a subnet that is BEHIND the client.

eg:

desktop -> MainFGT   <-VPNSSL  <- subFGT = officesubnet

and I want "desktop" and "officesubnet" to be able to communicate.

packet capture on MainFGT says that packets for "officesubnet" enter the virtual
SSL-VPN(ssl.root) interface...
but they dont seem to  emerge on the "subFGT" router.

I've tried adding a static route for the subnet to the IP address that subFGT gets assigned for the tunnel..
but the route table always zeros out the Gateway IP to 0.0.0.0
Can anyone help me out with this?

24 REPLIES 24
PRosenlind
New Contributor III

I guess a simple solution would be to change VPN type to a classic Site-to-site tunnel, but I assume that's not possible in your case? 

FCSS SDWAN EFW
FCSS SDWAN EFW
pbrown134

exactly. ipsec is blocked, we have to use sslvpn

msanjaypadma
Staff
Staff

Hi @pbrown134 ,

 

Are you using FortiGate as SSLVPN client, if yes , can you just check and confirm did you configured as below article? 
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/508779/fortigate-as-ssl-vpn-client

If this is not the case, can you share relevant routing logs and sniffer and debug flow logs?

Mayur Padma
pbrown134

routing.. "logs"?

 

pbrown134

(yes, fortigate as client as i said in my initial post)

Also, that article only refers to setting up the base connectivity. It does not help with routing through the ssl-vpn client, to a network that is specifically behind the client.

Toshi_Esumi
SuperUser
SuperUser

I remember we had the same conversation a month or two before. It's not designed to do routing through without NAT. That's why it's NATed in the policy.

If IPsec is blocked you might want to try IPsec over GRE. It might not look inside of the GRE tunnel to block it.

 

Toshi

pbrown134

Trying to do business through UAE.
They look for anything that looks like vpn traffic and block it.
So, it HAS to be sslvpn

pbrown134

@Toshi_Esumi Could you help me find the particular prior post you mentioned, please?

Toshi_Esumi

It was just "it's not designed to work like you described". So it wouldn't help you.

 

Toshi

Labels
Top Kudoed Authors