SSL VPN For Remote Users - Fortinet Cookbook
SSL VPN For Remote Users - Fortinet Cookbook
FortiOS 5.6 is now available: Release Notes | What's New | Upgrade Path
FORTIGATE / FORTIOS 5.2 / FORTIOS 5.2.0 / FORTIOS 5.2.1 / FORTIOS 5.2.2 / FORTIOS 5.2.3 / FORTIOS
5.2.4 / FORTIOS 5.2.5+ / VPNS
SSL VPN for remote users
Posted on June 13, 2014 by Keith Leroux
http://cookbook.fortinet.com/sslvpnforremoteusers/ 1/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
This example provides remote users with access to the corporate network using SSL VPN and
connection to the Internet through the corporate FortiGate unit. During the connecting phase, the
FortiGate unit will also verify that the remote user’s antivirus software is installed and current.
http://cookbook.fortinet.com/sslvpnforremoteusers/ 2/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
1. Creating an SSL VPN portal for remote users
Edit the full-access portal. The full-access portal allows the use of
tunnel mode and/or web mode. In this scenario we are using both
modes.
In short, trafៜ�c intended for the Routing Address will not be split
from the tunnel.
You must include a username and password. You will create this
user in the next step, so be sure to use the same credentials.
2. Creating a user and a user group
Add a remote user with the User Creation Wizard (in the example,
twhite, with the same credentials used for the predeៜ�ned
bookmark).
http://cookbook.fortinet.com/sslvpnforremoteusers/ 3/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
Add the user twhite to a user group for SSL VPN connections.
3. Adding an address for the local network
Add the address for the local network. Set Subnet / IP Range to the
local subnet and set Interface to an internal port.
4. Configuring the SSL VPN tunnel
Go to VPN > SSL > Settings and set Listen on Interface(s) to wan1.
5. Adding security policies for access to the Internet and
internal network
Set Source Address to all and select the Source User group you
created in step 2.
6. Setting the FortiGate unit to verify users have current
AntiVirus software
7. Results
Log into the portal using the credentials you created in step 2.
http://cookbook.fortinet.com/sslvpnforremoteusers/ 5/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
Go to VPN > Monitor > SSL-VPN Monitor to verify the list of SSL
users. The Web Application description indicates that the user is
using web mode.
Go to Log & Report > Trafៜ�c Log > Forward Trafៜ�c and view the
details for the SSL entry.
Go to VPN > Monitor > SSL-VPN Monitor to verify the list of SSL
users.
The tunnel description indicates that the user is using tunnel mode.
Go to Log & Report > Trafៜ�c Log > Forward Trafៜ�c and view the
details for the SSL entry.
http://cookbook.fortinet.com/sslvpnforremoteusers/ 6/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
Download
About Latest Posts
Keith Leroux
Technical Writer at Fortinet
Keith Leroux is a writer on the FortiOS 'techdocs' team in Ottawa, Ontario. He obtained a
Bachelor's degree from Queen's University in English Language and Literature, and a
graduate certiៜ�cate in Technical Writing from Algonquin College. He spent a year teaching
ESL in South Korea. Annyeong!
http://cookbook.fortinet.com/sslvpnforremoteusers/ 7/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
Leave a Reply
Connect with:
Powered by OneAll Social Login
Join the discussion
Chris Mahoney
Also you might want to add that under System > Settings you need to change the
listening HTTPS port from 443 to 4433 or 4444 or something else than 443. This
will prevent the con៙�ict of the 443 trafៜ�c going to the management login.
Adam Bristow
Hello Chris,
Thank you for your comment! This can also be remedied by changing the
Listen on Port ៜ�eld to 10443 under VPN > SSL > Settings (in step 4). I will
make the change immediately.
If you’d like, check out the more recent 5.4 version of this recipe here:
http://cookbook.fortinet.com/ssl-vpn-using-web-and-tunnel-mode-54/
Best regards,
Adam
http://cookbook.fortinet.com/sslvpnforremoteusers/ 8/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
Juliet Bell
Using VPN to access work computer from home is secured and good, but VPN is
costly, Instead, I would recommend use of on premise remote support solution
such as R-HUB remote support servers. It works from behind your ៜ�rewall and is
only one time cost.
MatthiasB
Victoria Martin
Hi Matthias,
If you mean use a different IP than what is in the recipe, then yes, you
should be using the real IP of your wan1 interface. The IPs in our recipes
are just used as examples and are almost always IP addresses that are
restricted for private networks (172.20.x.x, 192.168.x.x, and 10.10.x.x).
Toshi Esumi
Since the handbook 5.2 contained wrong info especially for the policies, I opened a
TT#1526539 and I was directed to this page. It works but the tech conៜ�rmed NAT
was never needed on the policy.
http://cookbook.fortinet.com/sslvpnforremoteusers/ 9/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
Keith Leroux
Hello Toshi,
I plan to update the 5.2 handbook chapter as soon as possible. Thank you
for your comment!
PetrM
Hi Keith,
Thank you for the recipe.
Is it possible to limit access for speciៜ�c SSL VPN portal from speciៜ�c hosts?
Keith Leroux
Hi Petr,
PetrM
Hi Keith,
http://cookbook.fortinet.com/sslvpnforremoteusers/ 10/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
Keith Leroux
Hi Petr,
PetrM
Hi Keith,
Dan Farrell
This does not include the option for “routing address” and the handbook does not
describe it. This is a feature that has been added without deៜ�nition, description, or
example. Please add something about this.
Keith Leroux
Thanks Dan! I’ve updated the recipe to describe Routing Address. The SSL
VPN Handbook chapter will be updated shortly.
Cheers~
http://cookbook.fortinet.com/sslvpnforremoteusers/ 11/12
4/16/2017 SSL VPN for remote users Fortinet Cookbook
CONTACT | DOCUMENTATION LIBRARY | CLI PORTAL | FUSE | VIDEOS | SUPPORT | CORPORATE | LEGAL
© 2017 Fortinet
http://cookbook.fortinet.com/sslvpnforremoteusers/ 12/12