Skip to main content
Contributor III
August 12, 2008
Question

Installing the FortiSSL adapter for my road warriors!

  • August 12, 2008
  • 8 replies
  • 4029 views
Hey, I’ve a bit of a predicament on my hands. We recently installed a 300a, fortios 3 mr6 patch2, for a client and now we need to ensure that the laptop users can use the SSL VPN. Due to some fairly complex rules we’d like them to bring up a tunnel from the portal. That means they need to install the FortiSSL adapter but as the users don’t have admin rights they won’t be able to do the install themselves. To make matters more tricky the laptops are all in distant locations. They do however connect to the MPLS network during the day so we can get to them via RDP/VNC. I’m wondering if there is a way I can logon to each laptop as an administrator then install the CAB file. When they get home they can hit the portal and bring the tunnel up? Any ideas folks? I can imagine that others may of come up against this as we wouldn’t want our road warriors having admin rights now would we;-) Cheers, Greg

    8 replies

    Contributor III
    August 14, 2008
    I was rather hoping that someone might of come up against this one and have a solution for me! I' ll create a ticket and feedback when I get a solution. Cheers, Greg
    Carl_Wallmark
    New Member
    August 14, 2008
    Hi, Download the SSL Client (.MSI) of MR7 and use a tool called PSEXEC (http://www.ss64.com/nt/psexec.html) to deploy it. Never done it myself with the SSL client, but could work =)
    Contributor III
    August 14, 2008
    Thanks for the advice. Unfortunately we haven' t deployed MR7 to any of our devices yet! I don' t have a dev box to play with either:-( Don' t suppose there is any way you could get the MSI to me is there? That' s probably a naughty question that I shall get slapped for;-) You say in MR7 it' s an MSI? Does that mean that when you go to activate the tunell it starts an MSI installer? Completely off topic but are you using SIP at all and if so are there any real life improvements in MR7. All my reading do far tells me that most people turn off the helpers, ALG etc and open the ports! Many thanks, Greg
    Maik
    New Member
    August 14, 2008
    this MSI is to " offline" install the SSL VPN stuff on your client. This SSL VPN client can then be used by your users to dial in without navigating to the website. The SSL VPN Client from MR7 seems to work with FGT running MR5 too. If you use Client Certificate Auth, the FGT should be MR6p2. Ask your reseller for the MSI.
    Carl_Wallmark
    New Member
    August 14, 2008
    The SSL Client for MR7 works with MR6 and MR5 as well, you dont need to use a web browser anymore, it´s a " real" client. after install, go to Start->Program->Fortinet->Fortinet SSL Client. I have one customer who uses SIP, and i have turned off the SIP helper.
    Contributor III
    August 14, 2008
    Selective - many thanks!! Your tip helped me out greatly! -Tom
    Carl_Wallmark
    New Member
    August 15, 2008
    Great ! Did you use the PSEXEC tool ?
    Contributor III
    August 15, 2008
    I' d hope to push the MSI via Group Policy. Will feedback on that later next week. Do we know if the user needs power user or local admin rights to run the program? I installed the MSI for a user today and then got them to test over the UK Vodafone 3G and I couldn' t get them connected. It showed a session in the SSL monitor on the FG but it wouldn' t connect them. Quite strange. I ended up changing the port to 443 in case Vodafone were blocking. That still didn' t work so I elevated the user to power user then a local administrator. Still no joy. Could be a GPO for the windows firewall messing up the connection coming back from the FG. The user will try from home so that should exclude Vodafone. Cheers, Greg
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!