So it's an odd issue. Got some "file" servers, basically Synology/Netgear NAS boxes which users connect to whilst in the office, and remotely especially in the last few months.
The last Synology I added recently (Synology FS1018, let's call it SYN3), it was all configured, all good, working internally just as you'd expect it to, but for some reason, cannot ping it or access it over IPSEC VPN! The other Synology's are fine (SYN1 and SYN2), along with other servers.
Nothing special with rules etc, the IPSEC VPN is configured to access everything on the Local LAN, which the servers are part of, but just this one server is the problem. I looked at the SYN3, there is no firewall or any security settings causing any block within the Synology OS itself, it can be accessed just fine internally, and the VPN subnet is an extension of the local LAN, albeit a different IP range.
From the firewall, I can ping SYN3 just fine, using either DNS or it's IP, but not from the VPN clients!
Any ideas why I cannot communicate this particular server that may spring to mind?
It's the FG100E, on 6.2.3 firmware.
I am lucky in the sense that the users connect to their PC's via remote desktop once on the VPN, they can then access the servers, including the problematic one just fine, but if they tried to map a network drive to this particular Synology from their own personal PC's at home, which they may need to access a file quickly, it fails.
1- enable NAT on the inbound policy. This will make the VPN clients appear as local hosts. If it works, it might be a solution for you.
2- usually, NAT that fixes something not working otherwise is a poor workaround for defective routing. My first thought also was "default route incorrect". But you've excluded this possibility already.
3- you could just sniff the traffic to the SYN3 to see if traffic from the VPN client reaches the server, and whether it is returned, and if so, to which destination addresses.
Network & Internet > VPN. Click on your VPN name. If you want, at this point you can select Advanced Options to edit the connection properties, clear your sign-in info, or set up a VPN proxy. Select Connect and enter a password if you've set one. It can help you. Moreover, I suggest you buy a virtual service from https://intergrid.com.au/virtual.php if you don't want to have the same problem in the future. They have the cheapest prices and they work perfectly with the clients.
Hello, sorry, been busy with other work so this weekend I re-looked at this.
So gateway settings on SYN3 were definitely fine, same IP address.
I then enabled NAT on the IPSec VPN policy and it worked! Thanks.
What doesn't make sense is why all the other servers worked without NAT being enabled, but this particular server wasn't responding if NAT wasnt enabled. Maybe next weekend I'll be on site once again and I'll do another test as it's bugging me why only this server.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.