Skip to main content
acp
Staff
Staff
May 1, 2020

Technical Tip: How to configure specific SSL VPN address pool to SSL VPN Users/Usergroup

  • May 1, 2020
  • 0 replies
  • 43106 views
Description
This article describes how to create different SSL VPN IP POOL address and assign to Specific Users/User Group.

Solution
Network Diagram.

User1 needs to assign SSL VPN IP POOL OF 10.1.0.0/16.
User2 needs to assign SSL VPN IP POOL OF 10.2.0.0/16.




1) Users and user groups configuration.



2) Create address group.





3) Create 2 SSL VPN profiles.





Inside SSL VPN  Profile -1.
Source IP POOL of SSVPN_TUNNEL_ADDR1 Group.
Add routing address if specific routing table is injected to FortiClient.




Inside SSL VPN profile - 2.





4) Go to VPN -> SSL -> Settings.

- Select the listen external interface (port1 in this case), listen port (10443).




5) Create policy.

Configure policy to active SSLVPN and allow access.

NOTE:
Specific usergroup has to be set on both kind of policy.

- Go to Policy & Objects-> Policy -> IPv4.




Result.

1) User1.





Route print at client Windows machine.




2) User2.


Route print.






Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!