Skip to main content
1ryan1
Explorer II
July 28, 2022
Question

FortiClient - split and full tunnel options to FortiGate

  • July 28, 2022
  • 4 replies
  • 2062 views

Currently using Cisco Anyconnect where if a user wants to tunnel all or use their local Internet (split tunnel) they can choose to by selecting the appropriate group in the AnyConnect window. Does FortiClient allow you do this? If not, are there workarounds for users who require this feature (sometimes they need to be sourced from corp public IP).

4 replies

Anthony_E
Staff
Staff
July 31, 2022

Hello Ryan,

 

Thank you for using the Community Forum.

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Best Regards
Anthony_E
Staff
Staff
August 4, 2022

Hello Ryan,

 

I have found this document:

 

https://docs.fortinet.com/document/fortigate/6.0.0/cookbook/307303/ssl-vpn-split-tunnel-for-remote-user

 

Could you please tell me if it helps?

 

Regards,

Best Regards
1ryan1
1ryan1Author
Explorer II
August 4, 2022

Thanks for the update.

 

It appears that sets up a split tunnel for a user part of the sslvpngroup. How does that same user use the FortiClient to do a full tunnel back to corp, assuming the split tunnel is already in place?

1ryan1
1ryan1Author
Explorer II
August 4, 2022

Is it possible to use a VDOM to separate the split tunnel/full tunnel policy?