FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
gmarcuccetti
Staff
Staff
Article Id 190884

Description
This article describes how to disable local network access for SSL VPN while split tunnelling is disabled.

Solution
This feature for SSL-VPN can be set up to control local LAN traffic, in order to forward it all to the FortiGate.
Enable exclusive-routing via CLI inside the preferred portal, full-access in this example:

# config vpn ssl web portal
    edit full-access
      set exclusive-routing enable
    next
end   

Here there is an example of the feature that works with FortiClient.
Windows network setting :
- Local LAN 192.168.100.19/21.
- SSL VPN address 10.212.134.200.



 
 
Test:
Ping from Windows machine to 8.8.8.8.
 
 
 
 
Sniffer packet on remote FortiGate.
 
 

 
 
Ping from Windows machine to 192.168.100.41 (internal LAN).  
 
 
 
 
Sniffer packet on remote FortiGate.
 
 
       
 
In this example, the packets are not responded to due to a missing policy to allow the ICMP traffic.
 
Note.
To use 'set exclusive-routing enable' with FortiOS 6.4 FortiClient 6.4.2 is needed at least.

 

 

Related Articles

Technical Tip: Enabling SSL VPN Full Tunnel

Contributors