Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

subnet mask problem with ssl tunnel VPN

The tunnel VPN almost worked the way I wanted it to. It picked up one of the reserved IP addresses, but the subnet mask was 255.255.255.255 instead of 255.255.255.0. I set up the destination network with a subnet mask of 255.255.255.0 so I don' t know why it used the other subnet mask. Does it matter what interface I set the network to.? Right now I have it set to ANY.
29 REPLIES 29
rwpatterson
Valued Contributor III

The work station will always have the 255.255.255.255 subnet mask, because the IP address is a single entity, not a network. The source must remain at ' any' . The destination could be anything from a single entity, to a group, to a ' multiple' entity with a combination thereof.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

So if the mask is supposed to be 255.255.255.255, how do I communicate with the server so I can access my files?
rwpatterson
Valued Contributor III

On the DHCP server, you create the entry with the correct subnet mask (255.255.255.0). On the work stations, the subnet mask will be 255.255.255.255, with each station having a UNIQUE ip address.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

I guess I don' t know what you mean by " create the entry." The address was already in the DHCP scope with a subnet mask of 255.255.255.0.
rwpatterson
Valued Contributor III

' The entry' refers to the DHCP server configuration. You already created it. The workstation will have the single IP address subnet (255.255.255.255). That is normal. Routing is a whole different animal. If you have an IP address, you should be able to get to your files if its permitted the policy(s). Can you ping the server? Start with the basics.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
doshbass
New Contributor III

Paul, Is there actually a problem here? Is any communication not working that you expect to work, because it looks to me like the FG is doing everything it is supposed to.
Still learning to type " the"
Still learning to type " the"
Not applicable

rwpatterson, No, I cannot ping the server from the remote computer. I can ping it on the Fortinet VPN screen though. I was trying to map drives but couldn' t. After doing an IPCONFIG /ALL I noticed the different subnet mask, but apparently that is not the problem. The only thing I' ve been able to to is RDP, but that was going through the FortiNet VPN screen instead of the remote computer.
rwpatterson
Valued Contributor III

Is this setup in web mode?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

No, this is the tunnel mode. But I have the same issue with web mode. I can only RDP. I can' t access any files using FTP. The web bookmarks do work though (in web mode, not tunnel).
Labels
Top Kudoed Authors