Skip to main content
ssan239
Explorer II
July 12, 2024
Question

FQDN in Split Tunnel

  • July 12, 2024
  • 3 replies
  • 1842 views

Hi Team,

I went through the below link

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Access-to-Specific-FQDN-using-Split-Tunnel-SSL-VPN/ta-p/190062

 

As per the link we dont need to call the FQDN object in the split tunnel config but just creating the ACL with FQDN will create a route in the routing table? Is my understanding right?

 

Regards,

Sanjay S

3 replies

ozkanaltas
Valued Contributor III
July 12, 2024

Hello @ssan239 ,

 

Yes you are right. 

 

If you select "Enabled based on Policy Destination" on the tunnel portal configuration page. FortiGate will create a route for your client with an fqdn object which is used on policy. 

saimank1
New Member
July 12, 2024

I removed the split tunnel from VPN and add FQDN into policy. But now, all internet traffic route to VPN tunnel. How to make only route that FQDN through the VPN tunnel? Thanks https://mobdro.bio/ .

hbac
Staff
Staff
July 12, 2024

Hi @ssan239,

 

Split tunneling must be enabled. Just make sure 'Routing Address Override' is empty. 

 

Regards, 

ozkanaltas
Valued Contributor III
July 12, 2024

Hello @saimank1

 

Do you have a ssl-vpn policy with destination object "all"? if you say yes, you need to change this with a specific destination. Because "all" means 0.0.0.0/0.