I have a partially working SSLVPN setup between 2 fortinets.
The tunnel itself comes up fine.
What I'd like to be able to do, is route packets from/through the main router, to a subnet that is BEHIND the client.
eg:
desktop -> MainFGT <-VPNSSL <- subFGT = officesubnet
and I want "desktop" and "officesubnet" to be able to communicate.
packet capture on MainFGT says that packets for "officesubnet" enter the virtual
SSL-VPN(ssl.root) interface...
but they dont seem to emerge on the "subFGT" router.
I've tried adding a static route for the subnet to the IP address that subFGT gets assigned for the tunnel..
but the route table always zeros out the Gateway IP to 0.0.0.0
Can anyone help me out with this?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I guess a simple solution would be to change VPN type to a classic Site-to-site tunnel, but I assume that's not possible in your case?
exactly. ipsec is blocked, we have to use sslvpn
Hi @pbrown134 ,
Are you using FortiGate as SSLVPN client, if yes , can you just check and confirm did you configured as below article?
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/508779/fortigate-as-ssl-vpn-client
If this is not the case, can you share relevant routing logs and sniffer and debug flow logs?
routing.. "logs"?
Created on 05-03-2023 02:46 PM Edited on 05-05-2023 01:29 AM By Stephen_G
(yes, fortigate as client as i said in my initial post)
Also, that article only refers to setting up the base connectivity. It does not help with routing through the ssl-vpn client, to a network that is specifically behind the client.
I remember we had the same conversation a month or two before. It's not designed to do routing through without NAT. That's why it's NATed in the policy.
If IPsec is blocked you might want to try IPsec over GRE. It might not look inside of the GRE tunnel to block it.
Toshi
Trying to do business through UAE.
They look for anything that looks like vpn traffic and block it.
So, it HAS to be sslvpn
@Toshi_Esumi Could you help me find the particular prior post you mentioned, please?
It was just "it's not designed to work like you described". So it wouldn't help you.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.