How to configure SSL VPN in fortigate V4
How to configure SSL VPN in fortigate V4
Access for permitted remote networks and all other services passing the regular default gateway
1. Create user group and users:\
Go to: User > User > User (create new)
Enter User name and password

Go to: User > User group > User group (create new)
Enter group name
Enter group name
Type: mark Firewall
Mark Allow SSL-VPN access
Choose tunnel-access

Move users to Members of group

2. Addresses
Use default IP addresses pool for SSL VPN users or create new one

Create new address object for network that should be reachable via SSL VPN
Go to: Firewall Objects > Addresses > Addresses (create new)
Add address name
Type should be Subnet / IP Range
Add address and mask
Choose interface

3. SSL VPN configuration:
Go to: VPN > SSL > Config
In IP pools you can choose address object previously configured for VPN users or leave default (SSLVPN_TUNNEL_ADDR1)
Do not change all other parameters

Go to: VPN > SSL > Portal
Mark tunnel-access and choose edit

Choose edit in Tunnel mode window

Name: enter name
IP mode: choose User Group
IP Pools: add address object previously configured for VPN users or leave default (SSLVPN_TUNNEL_ADDR1)
Mark Split Tunneling to permit services with destination not behind the Firewall to pass via regular default gateway
Press OK

4. Add static route for SSL VPN users network (default: SSLVPN_TUNNEL_ADDR1) or previously configured
Enter destination network (SSL VPN users network)
Device should be ssl.root

5. Rules configuration:
We have 3 networks:
port1(Wan-Telecity) – external network
ssl.root – VPN SSL network
Lova-Test – internal network
Create rule from External to ssl vpn tunnel interface

And click on ADD button:
User Group: choose previously configured users group for VPN
Service: ANY
Schedule: always

Create rule from ssl.root to internal network

Create rule from External to Internal with SSL VPN action

And click on ADD button:
Same config

6. Use Forti Client to establish SSL VPN connection
Choose VPN connections

Click on “+” to create new connection

Add connection name
Type: SSL VPN
Remote Gateway: External firewall address

Mark “test” VPN connection and press connect

Enter Password than OK





And you connected
Made by:
XGlobe networking department