FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rvillaroman
Staff & Editor
Staff & Editor
Article Id 315922
Description This article describes how to access internet connections on the SSL VPN client to specific internet networks without disabling split tunneling on the SSL VPN portal.
Scope All FortiGate versions. 
Solution
  1. Create a new SSL VPN portal and add the IP address of the specific internet network on the routing address override. If there is an existing portal, just add the IP address on the routing address override.

    Picture1.png
  2. In this example, the IP for the acme.com is used.

    Picture2.png
  3. Apply the created SSL VPN portal to the SSL VPN Group authentication and portal mapping.

    Picture3.png
  4. Create a new firewall policy for the SSL tunnel interface to the WAN port.

    Picture4.png

 

The result:

Once connected to the SSL VPN client, it will inject the route to the specified internet network through the SSL VPN gateway.

Picture5.png

The website is now accessible, and traffic is passing through the SSL VPN even though split tunneling is enabled.

 

Picture6.png

 

Note: If the website to be added has multiple DNS IP addresses, it is necessary to add all of the subnets on the routing address override.

  • Starting with FortiOS 7.6.3, SSL VPN tunnel mode has been removed from both the GUI and CLI.
  • Settings related to SSL VPN tunnel mode will not be carried forward during firmware upgrades.
  • This change applies to all FortiGate models.
  • To ensure uninterrupted remote access, administrators must migrate their SSL VPN tunnel mode configurations to IPsec VPN before upgrading to FortiOS 7.6.3.