Skip to main content
Contributor III
August 19, 2006
Question

SSL-VPN: Restrict destinations by group?

  • August 19, 2006
  • 11 replies
  • 6756 views
Hi everyone. I' ve been scratching my head on this one: I' d like to restrict what destination IP addresses on the protected network are reachable via ssl-vpn client groups. I thought this would be doable by defining a wide SSL-VPN range, then restricting which addresses were actually assigned on connection via the SSL-VPN group settings (restrict IP tunnel range), and finally creating a SSL-VPN policy which explictly states the source and destinations allowed and assigning the appropriate group(s). It seems as if this should work, but alas; it does not and I' m left banging my head. Everyone SSL-VPN' ing in can access everything on the said protected subnet. What am I missing?

    11 replies

    weinsjs
    New Member
    August 19, 2006
    Hi Brian, I have same problem. I have two FortiGate 500' s in A-A HA and not comfortable enough with moving from 2.8 to 3.0 for production. So, I am using an FG60 for SSL VPN purposes off one of the interfaces. Upon configuration, I had/have the same problem. I ended up " patching mine" by configuring the policies on both the FG60 and the FG500. It is duplicate (which stinks) but met with my goal. I don' t know if this is a known bug or just something I missed as well. Take care weinsjs
    Contributor III
    August 21, 2006
    Hi, Had the same problem, and knocked my head against the wall before giving in and calling support. I guess I could have saved myself a headache, as according to support, this is a feature request for MR4. Until then, you set one policy for access and the destination. If you put in more than one SSL policy, the least restrictive seems to take effect. It seems to take (no matter what source you put in the policy address) the address field for Source from the range of IP addresses set up in SSL VPN. After talking to the gentleman from Fortinet (who talked to escalation before getting back to me), I tried a few configurations and have found a " solution" of sorts. Do the following after setting up your basic SSL VPN configuration. Create two (or more) SSL VPN user groups. Split up your SSL VPN range into however many groups you want to configure. For example, if you had 192.168.1.10-20 set in the SSL VPN range, and you want to configure access for 2 groups, then the range could be split to x.10-15 for group a, and x.16-20 for group b. You would do this in the SSL User Group Options " Restrict tunnel IP range for this group " . Then create to address ranges, call the first ssl 10to15 and the second ssl 16to20, or whatever you want. Create your base (i.e. bottom position) SSL Authentication policy, i.e. WAN1, Address SSL VPN Entire Original Pool to Internal, Entire Private net, action SSL VPN. The create 2 policies that you will insert in front of it, one a policy that will deny action all access to the private net (middle position), and one policy that will allow action access to the restricted group to whatever specific machines you want to allow access (top position). In this setup, you end up with one restricted group, and a second (administrators?) unrestricted group. You can nest more allow/deny policies to tighted up as needed. Ok I know that is a bit confusing, so here' s a picture., it' s relatively simple once you get the idea. Think restriction by IP ranges, and SSL Action used once for authentication. Hope this helps.
    Contributor III
    August 29, 2006
    Thanks for the responses and suggestions. Walter, I' ll try your set up and see if it works. I' m a bit confused as to why it works, but I think I know how to get it set up. I guess we' ll wait for MR4! Does anyone know when that is supposed to be released?
    Contributor III
    August 30, 2006
    Let me know how it turns out for you. As for how it works, think Linux Ipchains/Iptables. Top down rule matching, with the deny as your " default" policy, and all the allow policies above designating actual access. The SSL VPN action at the very bottom is simply an " authentication" rule that you use to state who can use the VPN tunnel. The SSL VPN is not affected because the users do not have does source IP ranges until after they connect. However, once they connect, their source IP ranges (the private IP addresses on your LAN) changes and that' s when the policies above start to affect them. Walter
    Paul_Dean
    Visitor III
    November 14, 2006
    Thanks Walter. That was very useful indeed. I have also been able to access multiple interfaces across the SSL VPN too. Set it up as Walter describes, then create rules on the second interface pair to allow or deny access (as rules 34 and 35 above). You only need 1 authentication policy (as in rule 33).
    OnTheEdge
    New Member
    February 6, 2007
    I' m curious, did MR4 actually simplified this ? H@ns
    OnTheEdge
    New Member
    February 9, 2007
    Hello, just to let you know that I' ve used this procedure to restrict some users to some IP address in our network. But in our case, users are authenticated thru our RSA Secure ID appliance. It works great but it involves a lot of manual work. I just hope they will ease this a bit in a future release. H@ns
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!