Skip to main content
ChrisTan
Staff
Staff
February 18, 2025

Technical Tip: How to apply bypass subnet in the FortiSASE

  • February 18, 2025
  • 0 replies
  • 990 views
Description This article describes how to add subnets bypass in the FortiSASE.
Scope FortiSASE.
Solution

The FortiSASE default route goes to SIA, but in the below situation:

The PC IP address is 192.168.1.1/24, while the printer IP address is 192.168.2.1/24. The printer is unreachable once the SIA is connected.

 

In this case, the subnet 192.168.2.0/24 should be bypassed and routed by the local gateway. In the FortiSASE customized profile, there are only three types of bypass:

 

Infrastructure, FQDN, Local Application:

 

2025-02-17_10h47_37.png

 

In the FortiSASE SSL Instances, the subnet will only be available in the default profile (refer to the note at the end of this article).

 

2025-02-17_10h51_45.png

 

All profiles will apply once the bypass subnets are configured in the default profile, but it is greyed out and read-only:

 

2025-02-17_10h57_00.png

 

The PC can reach the printer once the bypass subnet 192.168.2.0/24 is added. 

 

The FortiClient config can be found in:

 

C:\Users\"username"\AppData\Local\FortiClient\fortisslvpn_xml.txt

 

It includes the below:

 

<split-tunnel-info negate='1'><addr ip='192.168.2.0' mask='255.255.255.0' /></split-tunnel-info>

 

The 192.168.2.0 255.255.255.0 goes to the local gateway and can also be found in the local PC 'route print'.

Important Considerations:

 

FortiSASE with SSL VPN remote user connectivity:

  • Host groups are supported when the Subnet match type is used, provided they exist in Configuration -> Hosts.

  • Subnet or IP range destinations can only be defined in the Default endpoint profile. Any subnet destinations configured in the Default profile are inherited by all custom endpoint profiles.

FortiSASE with IPsec VPN remote user connectivity:

  • Subnet configuration is limited to manual entry in the Create Destination dialog.

  • Subnet destinations can be configured separately in both Default and custom endpoint profiles.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!