Skip to main content
pksubramanian
Staff
Staff
September 3, 2019

Technical Tip: Enabling SSL VPN Full Tunnel

  • September 3, 2019
  • 0 replies
  • 13403 views

Description


This article describes how to enable SSL VPN Full Tunnel.
When an SSLVPN user connects to FortiGate with a Full Tunnel VPN profile, a default route is injected into the user machine. 
However, the directly connected local segment (on link) of the laptop will still be accessible.

Example with laptop@192.168.86.202 which is able to access 192.168.86.205 :

 

local segment: 192.168.86.x
Laptop: 192.168.86.202
onlink resource: 192.168.86.205

 

Scope

 

FortiGate.


Solution


To prevent SSL VPN users from accessing the “on link” resource, configure “exclusive-routing enable”:

 

config vpn ssl web portal
    edit full-access                   <------------- Respected SSLVPN TUNNEL

        set exclusive-routing enable   <------------- Enable
end

 

Note: 

This feature is not compatible with application-based split tunnels (configurable for FortiClient VPN profiles in EMS). Application-based split tunneling takes precedence and disables exclusive-routing.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!