Description
This article describes how to disable the 'Split-Tunnel' feature and create an IPv4 policy for WAN access.
Scope
FortiGate.
Solution
Disabling the 'Split-Tunnel' option for SSL VPN or IPSec Dialup.
For SSL VPN refer to the following:
Go to VPN -> SSL VPN Portals -> Edit SSL VPN Portal and under 'Tunnel Mode' disable 'Enable Split Tunneling'.
For IPSec Dialup refer to the following:
Go to VPN -> IPSec Tunnels and under Network, the option for IPv4 Split Tunnel must be disabled.
To disable the IPv4 split tunnel in the CLI:
config vpn ipsec phase1-interface
edit dialup
unset ipv4-split-include
next
end
Once the IPv4 split tunnel is disabled, a firewall policy from the IPSec Dialup to the WAN policy is needed.
To create the firewall policy in the CLI:
config firewall policy
edit 0
set name "IPsec to WAN"
set srcintf "dialup"
set dstintf "virtual-wan-link"
set action accept
set srcaddr "dialup_range"
set dstaddr "all"
set schedule "always"
set service "ALL"
set nat enable
next
end
Note:
Doing changes in the IPsec VPN while a user is active will disconnect them. It will then be necessary to reconnect.
Related article:
Technical Tip: Disable split tunneling to specific groups and enable it to other group/users
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.