Skip to main content
itelysium
New Member
November 22, 2024
Question

SSL-VPN Sysadmin Access (Fortigate 100F)

  • November 22, 2024
  • 2 replies
  • 749 views

Dear Forum Community ,

 

I want to access remote in my working company and have acess in all vlans . The infastructure of my fortigate is the bellow :

Interface WAN: For Access in ISP 

Interface Trunk with subinterface: Vlan1,Vlan2, Vlan3 etc 

 

I do all the settings with ssl-vpn address and i want to have one firewall policy to access and administrate all VLANs. 

2 replies

AEK
SuperUser
SuperUser
November 22, 2024

Hello

Add a firewall rule like this:

  • Src intf: SSL-VPN Tunnel Interface
  • Src: SSL_VPN_address_range + SSL_VPN_user_or_group
  • Dst intf: VLAN1, VLAN2, VLAN3
  • Dst: all
AEK
funkylicious
SuperUser
SuperUser
November 22, 2024

Hi,
Exactly how @AEK  described it, just keep in mind that you would need to activate this feature in order to have multiple interfaces in one policy which is not enabled by default.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-allow-the-configuration-of-policies-with/ta-p/191941

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!