hi,
having an issue brought up a lab.
2 fortigate 2500e working in ha active-passive.
version 6.0.10-FW-build0365
two vdoms x,y.
configured sslvpn separately for each vdom.
no vdom links between the vdoms.
when a sslvpn user in vdom x connects he gets an ip address from dhcp pool that is configured in sslvpn vdom y.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi miz65,
make sure the two vdoms are not having some DHCP relay configured, one relaying to another.
The DHCP pool should not matter, because normally the pool is taken from a default configuration and ip pool object of the 10.212... range.
See how your client IP assignment is working, or supposed to work.
In case of DHCP you could use the dhcps debug, in case of the SSLVPN assigning it from its pool, see to run the sslvpnd debug.
Another helpful command will be
diag firewall auth list
Which shows you which users got which addresses, which memberships if any and by what server configuration (name in your config) they have been authenticated.
Markus
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.