Technical Tip: Enabling SSL VPN Full Tunnel
Description
This article describes how to enable SSL VPN Full Tunnel.
When an SSLVPN user connects to FortiGate with a Full Tunnel VPN profile, a default route is injected into the user machine. However, the directly connected local segment (on link) of the laptop will still be accessible.
Example with laptop@192.168.86.202 which is able to access 192.168.86.205 :
local segment: 192.168.86.x
Laptop: 192.168.86.202
onlink resource: 192.168.86.205
Scope
FortiGate.
Solution
To prevent SSL VPN users from accessing the “on link” resource, configure “exclusive-routing enable”:
config vpn ssl web portal
edit full-access <------------- Respected SSLVPN TUNNEL
set exclusive-routing enable <------------- Enable
end
Note:
This feature is not compatible with application-based split tunnels (configurable for FortiClient VPN profiles in EMS). Application-based split tunneling takes precedence and disables exclusive-routing.
