Skip to main content
Shashwati
Staff
Staff
November 24, 2023

Technical Tip: How to configure split tunnel for SSL VPN using an address override

  • November 24, 2023
  • 0 replies
  • 15376 views
Description This article describes how to configure split tunnel for SSL VPN using address override
Scope FortiGate 6.X and 7.X
Solution
  1. Configure the SSL VPN user group.

 

5.PNG

 

  1. Configure SSL VPN Settings

1.PNG

 

2.PNG

 

  1. Configure the allowed subnet for the SSL VPN users.

10.PNG

 

  1. Configure the SSL VPN Portal using a Routing Address Override. The subnet allowed on this address override will only be accessible for SSL VPN users.

3.PNG

 

  1. Configure a Firewall policy:

4.PNG

 

  1. Configure the interface subnet as follows:

9.PNG

 

  1. The user will able to connect to the SSL VPN:

7.PNG

 

  1. The connected user will only be able to access the allowed subnet 192.168.1.0/24.

 

12.PNG

 

An example of a route print from the user's machine:

 

14.PNG

 

Note: User Internet traffic will not be forwarded to the tunnel. 

 

Related article:

Technical Tip: Enabling split tunnel feature for SSL VPN.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.