Skip to main content
Fenx
New Member
April 27, 2018
Question

SSL VPN - Split Tunnelling with exceptions

  • April 27, 2018
  • 2 replies
  • 9852 views

Hi everybody, I have a question about a technical feasibility on the Fortigate 600D range. I have a client who owns among other things a Fortigate 600D to go out on the Internet. From their personal home, users connect in SSL VPN via the Forti client with the "Split Tunneling" mode enabled on the Firewall to avoid cluttering the network and exit on the Internet via their local gateway (at home) and not the VPN-SSL of the company. It works very well, my client will just want to make a change to that. He would like for only 3 Internet links (http or https) to exit via the SSL VPN and to squeeze the "Split Tunneling" but only for these 3 Internet links. (3 public IP addresses). Thank you very much for the answer you can give me.

    2 replies

    Fenx
    FenxAuthor
    New Member
    April 27, 2018
    I know I have to add an FQDN object in Routing Address in "Enable tunneling" but we can add only a network or a fixed ip.

    Thanks.
    saneeshpv_FTNT
    Staff
    Staff
    May 6, 2018

    You will be able to add multiple entry in the list of Routing Address where you enabled Split Tunnel.

    Refer attached image.

     

    Hope this is what you are looking for.

    Regards,

    Saneesh

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!