Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bsgroup
New Contributor

ssl-vpn let client reach devices in the same subnet of the wan

Hi all,

Actually I'm testing my new fortigate 60f and for test I have this configurations:

modem -> oldFirewall (wan ip 10.0.0.10; lan 20.0.0.1) -> fortigate (wan ip 20.0.0.10; lan 192.168.10.1)

I can can connect to forticlient but actually I cannot ping any device in the same subnet of wan connection. for example I cannot ping 20.0.0.20-254 devices) 

 

can some one help me which setting let clients to reach all devices also that devices connected to the old firewall?

many thanks in advance

1 Solution
AEK

So you mean switch1 is L3 and the IP 30.0.0.1 is owned by that switch, right?

If this is the case then you have two choices:

  • If you don't really need your switch to be L3, then convert it to L2 switch and put the gateway 30.0.0.1 on FortiGate instead
  • Otherwise, you can add default gateway to your switch pointing to FortiGate, and add a route on FortiGate to reach network 30.0.0.0/24 through the L3 switch
AEK

View solution in original post

AEK
8 REPLIES 8
AEK
SuperUser
SuperUser

Hi

Add the following firewall policy:

  • Source: ssl_vpn / ssl_vpn_address_pool
  • Destination: WAN interface / 20.0.0.0/24
  • NAT: Enabled

Then connect to SSL VPN again and it should work.

AEK
AEK
bsgroup
New Contributor

many thanks in advance...just one more question. I'm trying set policy but I can't find wan option

can you help me?Screenshot 2024-02-12 080009.png

AEK

If I understand what you mean, you need to create an address object by clicking the "+ Create" button shown on your screenshot, then create an address object (lets call it "s-wan1") of type subnet with the value 20.0.0.0/24.

AEK
AEK
bsgroup
New Contributor

many many many thanks

it works...just one more question

 

if I have some machines with static ip 30.0.0.10 30.0.0.20 etc but I don't have any lan or wan on that subnet, how can i reach them in forticlient? I try adding the policy as myou suggest to me before, but I cannot reach them. these devices are just statics devices which I can reach adding on my laptop the adding gateway 30.0.0.1

 

there is a way to reach them connecting them to fortigate? many thanks again for your help

 

AEK

Do you mean that these devices are not directly behind FortiGate but are behind another router which is connected to FortiGate? In other words do you mean FortiGate doesn't have any interface with address 30.0.0.x/24?

AEK
AEK
AEK

Are you using public IP addresses on your network (20.x.x.x, 30.x.x.x)?. If this is the case than this is wrong, you have to use private addresses otherwise.

AEK
AEK
bsgroup
New Contributor

I have this situation:

modem -> router -> fortigate (not lan dhcp server until now) -> switch1

                                some machine with static ip (30.0.0.10...ecc/24) -> switch1

 

how can reach machines with static ip and gateway 30.0.0.1? I need ad a lan interface in the fortigate?

                           

 

AEK

So you mean switch1 is L3 and the IP 30.0.0.1 is owned by that switch, right?

If this is the case then you have two choices:

  • If you don't really need your switch to be L3, then convert it to L2 switch and put the gateway 30.0.0.1 on FortiGate instead
  • Otherwise, you can add default gateway to your switch pointing to FortiGate, and add a route on FortiGate to reach network 30.0.0.0/24 through the L3 switch
AEK
AEK
Labels
Top Kudoed Authors