Skip to main content
rickas27
New Member
March 3, 2026
Solved

Routing Address Override in SSL-VPN Split Tunnel

  • March 3, 2026
  • 1 reply
  • 762 views

We have several user groups mapped to separate, corresponding SSL-VPN Portals. Each of these portals has Split Tunnel Enabled Based on Policy Destination. Each of these portals also has Routing Address Override with network addresses that match the same "allowed destination" addresses in their corresponding policies.

 

Is Routing Address Override even needed?

According to Split Tunnel Enabled Based on Policy Destination, "Only client traffic in which the destination matches the destination of the configured firewall policies will be directed over the SSL-VPN tunnel."

So in an example where the Accounting network is 192.168.0.0/24 and a user is in the Accounting Group, which is assigned to the Accounting Policy (that allows access to the 192.168.0.0/24 network); Would I even need any address in the Routing Address Override for the Accounting SSL-VPN Portal?

From what I understand, any traffic to 192.168.0.0/24 would go over the SSL-VPN with Split Tunnel Enabled Based on Policy Destination. So what is the point of Routing Address Override?

 

I ask this because this is how all of our SSL-VPN Portals are configured (by an organization that preceded mine), and I'm looking to consolidate all the SSL-VPN Portals to a single one with no Routing Address Override (but with Split Tunnel Enabled Based on Policy Destination).

Best answer by Toshi_Esumi

"Routing Address Override" is GUI is "set split-tunneling-routing-address" in "config vpn ssl web portal" in CLI.

If you don't want to use the network address override but let the policies to inject the routes instead, you can do that but need to leave the box empty in GUI (unset split-tunneling-routing-address in CLI). Because the routing address override/split-tunneling-routing-address takes precedence over destination addresses in policies. 

Then there are some conditions in case one user belongs to multiple groups and those groups are set in different polcies. See the KB below.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-split-tunnel-portal-with-policy-based/ta-p/317584

Toshi

1 reply

Toshi_Esumi
SuperUser
SuperUser
March 3, 2026

"Routing Address Override" is GUI is "set split-tunneling-routing-address" in "config vpn ssl web portal" in CLI.

If you don't want to use the network address override but let the policies to inject the routes instead, you can do that but need to leave the box empty in GUI (unset split-tunneling-routing-address in CLI). Because the routing address override/split-tunneling-routing-address takes precedence over destination addresses in policies. 

Then there are some conditions in case one user belongs to multiple groups and those groups are set in different polcies. See the KB below.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-split-tunnel-portal-with-policy-based/ta-p/317584

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!