Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
growthvectors
New Contributor

IPsec VPN connection on v7.4.0 not working entirely

Hello,

 

After upgrading from V6.0.9 I created a new IPsec VPN, most of it works except one small detail.

When the VPN is active, trough FortiClient VPN, the connection to all internal resources works, browsing on the internet works, except when I want to connect to anything that has to be accessed through the firewall.

With the VPN active I can't connect to FortiGate admin portal. Anything that resolves to the WAN IP Address is getting dropped by the firewall, it is visible in the logs. There is a DNS server behind the firewall, but still the FortiGate admin Portal resolves to the WAN IP address and the connection is getting dropped by the firewall.

It jumps over the rule I created and applies the Implicity Deny rule created by default.

VPN rule is as follows:

Name:VPN-NEW

From: NewVPN

To: InternalResources, WAN

Source: NewVPN_range

Destination: all

Schedule:always

Service:ALL

Action: ACCEPT

IP Pool:

NAT: NAT

 Type:Standard

Security Profiles: SSL no-inspection

Log:All

 

I read the documentation for the IPsec VPN on 7.4.0, followed the steps and recreated the VPN step by step like in the documentation but still same issue. The VPN was created with the template type Remote Access & Pre-shared Key.

I checked on the forum but I have not found anything similar that could explain what might be wrong with the setup.

 

3 REPLIES 3
Jean-Philippe_P
Moderator
Moderator

Hello growthvectors, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

 

Thanks,

Jean-Philippe - Fortinet Community Team
pbhasuran
Staff
Staff

Hi growthvectors,

 

I believe you are trying to access FortiGate GUI using public the IP address via IPSEC VPN. The better option would be to route this MGMT traffic via an Internet link rather than using IPSEC VPN and access directly without VPN. 

If you want to access the GUI via IPSEC VPN, you can try to configure the loopback IP on the remote FGT and access the FGT via the same IP

Padman B
Labels
Top Kudoed Authors