Hot!SSL_VPN vlan interface on wan1

Author
mark14
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/01/15 14:17:43
  • Status: offline
2019/01/15 14:32:39 (permalink)
0

SSL_VPN vlan interface on wan1

Hello,
I am trying to configure SSL_Portal on dedicated public IP address. Currently wan1 IP is 91.x.x.30/32 and I added vlan interface (vlan id 1) to wan1 physical interface and I configured IP: 91.x.x.25/32. When I change interface in SSL_Portal to 91.x.x.x.25 I can reach vpn web portal from LAN network, but not from public network (internet). Also I added firewall rule in Local-In policy (allow from all source to 91.x.x.x.25) but it does not work. Should I do something else or it is better option to achive this in other way (ssl_vpn on dedicated virtual interface and public IP address)
Best Regards,
Mark

Attached Image(s)

#1

8 Replies Related Threads

    rohitchoudhary1978@gmail.com
    New Member
    • Total Posts : 13
    • Scores: 0
    • Reward points: 0
    • Joined: 2016/11/30 23:07:36
    • Status: offline
    Re: SSL_VPN vlan interface on wan1 2019/01/16 01:02:27 (permalink)
    0
    Hi,
    Try to change the listen port 443 to e.g., 10443. it should work.
     
    Rgds
    Rohit
    #2
    mark14
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/15 14:17:43
    • Status: offline
    Re: SSL_VPN vlan interface on wan1 2019/01/16 02:07:56 (permalink)
    0
    Unfortunetaly it does not help. As I said before I can reach vpn portal from LAN network, so technically it is some problem only from internet.
    #3
    brycemd
    Bronze Member
    • Total Posts : 49
    • Scores: 2
    • Reward points: 0
    • Joined: 2016/12/03 11:24:30
    • Status: offline
    Re: SSL_VPN vlan interface on wan1 2019/01/18 09:43:18 (permalink)
    0
    I guess the first question would be why are you using a VLAN? Does your ISP actually route that IP to you using a tagged VLAN?
    #4
    mark14
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/15 14:17:43
    • Status: offline
    Re: SSL_VPN vlan interface on wan1 2019/01/18 10:33:03 (permalink)
    0
    Fortigate is connected to BGP router not directly to ISP. I just wanted to achieve create virtual interface(connected to Wan1 physical interface) with directly assigned public IP address and set up it to ssl portal. I know that is VIP solution (create VIP with public IP and mapped to internal ip) but IMO what i want achieve is better.
    #5
    mark14
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/15 14:17:43
    • Status: offline
    Re: SSL_VPN vlan interface on wan1 2019/01/29 00:10:08 (permalink)
    0
    Any ideas how to achieve it?
    #6
    AtiT
    Platinum Member
    • Total Posts : 453
    • Scores: 38
    • Reward points: 0
    • Joined: 2012/04/18 12:13:27
    • Location: Prague / Czech Republic
    • Status: offline
    Re: SSL_VPN vlan interface on wan1 2019/01/29 00:35:52 (permalink)
    0
    Hello,
    I just want to understand your IP addressing. You have assigned some subnet 91.x.x.x/x.
    Are you sure that you have public IP 91.x.x.25/32 and 91.x.x.30/32? It seems to me that the subnet is wrong. Or it is some PPPoE or something else?
     
    So you have on your wan interface IP 91.x.x.25 and you created VLAN1 under your wan interface with IP addressing 91.x.x.30?
    This is how I understand your topology.
     
    It seems to me that here is some problem with subnets.
    Also I would recommend to not use VLAN 1 never ever.
    Is the VLAN configured on the BGP router also where your fortigate is connected?

    AtiT
    --------------------
    NSE 8, CCNP R+S
    #7
    mark14
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/15 14:17:43
    • Status: offline
    Re: SSL_VPN vlan interface on wan1 2019/01/29 01:05:54 (permalink)
    0
    I used /32 netmask because while creating vlan on wan1 interface appears invalid subnet. Fortigate is connected to BGP directly (RJ45 without any vlan, BGP reach 91.x.x.x/24 netmask). I am trying to create any type of interface and later choose it in SSL_Portal "Listen on interface". Maybe should I try with loopback interface? So there is no chance and I need set up VIP as follow:
     
    https://forum.fortinet.com/tm.aspx?m=111523
    #8
    mark14
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/01/15 14:17:43
    • Status: offline
    Re: SSL_VPN vlan interface on wan1 2019/01/30 06:38:12 (permalink)
    0
    Summarizing for this moment there is one solution? 
     
    ede_pfau
    hi,

    and welcome to the forums!

    There is no setting for specifying the IP directly.
    Instead, you could try to use a VIP with port mapping:
    Firewall objects > Virtual IP > Create new
    external IP: one of your WAN IPs
    external port: say, 20443
    mapped to : your primary WAN IP
    mapped to port: 10443 (default for SSL VPN)

    Then, create a policy:
    src IF: WAN
    src IP: all
    dst IF: WAN
    dst IP: your VIP
    service: custom service for tcp/20443
    schedule: ...
    action: accept
    NAT: no

    Give it a try and let us know how it works.

    #9
    Jump to:
    © 2019 APG vNext Commercial Version 5.5