Skip to main content
julianhaines
Explorer II
November 24, 2023
Question

Filtering outbound VPN traffic with Split Tunnel FortiGate 7.2

  • November 24, 2023
  • 2 replies
  • 3040 views

Below is my current setup to allow remote users to access my network via VPN, at the moment they all get the same Web Filter Policy but want to change so that users get a Web Filter Policy depending on the Group they are a member of, I am doing this with local traffic but cant see how this is done with VPN and Split tunnel.

 

Is this possible with Split Tunnel?

 

SSLVPN_TUNNEL_ADD1 is the DHCP range issued to VPN users, and VPN - Group DUO Radius Servers is the VPN Auth server.

 

Layout Version 2.png

 

 

2 replies

hbac
Staff
Staff
November 24, 2023

Hi @julianhaines,

 

If split tunneling is enabled, the destination of the firewall policy can't be all. 

 

Regards, 

julianhaines
Explorer II
November 29, 2023

Hi @hbac , thanks for the information, I have taken over the FortiGate from previous IT Admin and in the current outgoing ssl.root to Virtual-Wan-Link the destination is already set to "All" so don't know how this was done. 

 

If I disable Spit-Tunnel what would I change the "All" destination to? would it be 0.0.0.0 or the VPN DHCP range allocated to the VPN users or something else?

hbac
Staff
Staff
November 29, 2023

@julianhaines,

 

If split-tunneling is disabled, you don't need a firewall policy from ssl.root to Virtual-Wan-Link. You only need policy from ssl.root to lan. 

 

Regards, 

angus2
New Member
November 29, 2023

We wound up scrapping the idea of using EMS to split tunnel. We now have specified LAN networks at the head end on the VPN network, forcing all non-LAN traffic to route elsewhere.