Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ikmarwright
New Contributor III

Link to external (third party) VPN interferred with by FortiOS 5.6.5

Hi

 

Note: This is not a Fortinet VPN question. It's a FortiOS question.

 

I have a few employees using a non-Fortinet VPN connection to one of our customers. The connections (setup using Windows 10's built-in VPN settings) work fine outside of our office, but inside our office, connections are never finalized. The software connects, gives login information and then goes back to try connecting again. It never errors out. I have limited access to the machines (and no access to the customer VPN server) and can't test much (or often). I see nothing in the logs that suggest our FortiGate device is filtering access, but the client insists they are not blocking us in any way.

 

All I need is a point in the right direction. Where in the FortiOS might there be a setting restricting access to external VPNs?

4 REPLIES 4
Ashik_Sheik
Contributor II

Hi

 

IPSEC works on 2 UDP protocol No's (UDP 500 or 4500) and Fortigate there is Service called IKE need to allow on inside to outside policy to work VPn from inside .

 

Just check if they use IPSEC or other protocols .

 

Regds,

 

Ashik

Ashu 

 

Ashu
tanr
Valued Contributor II

Do you have the FortiGate doing Application Control and blocking Proxy?  That might be blocking your VPN connections.

ikmarwright
New Contributor III

Ashik: I know they aren't using PPTP or L2TP. I'm not sure if it's SSTP or IKE though. I'll look into the settings though.

tanr: We have some Application Control, but their IP isn't showing up in the log as being affected (which makes sense). I'll check my proxy settings, but I don't believe it's that either.

 

Thanks to both of you. Hopefully I'll get a chance it test it again this week.

emnoc
Esteemed Contributor III

diag debug  flow is your friend here. If yoou set the  policy to  and service to "any", does it work? What policy are you matching now? Is it  IPSEC ?

 

If yes for IPSEC  UDP500/4500 and protocol #50 ( yes protocol not port # for ESP )

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors