Description | This article explains, with scenarios, how to allow traffic from SSL VPN to IPsec when the remote side is only accepting traffic from a specific subnet or IP address. |
Scope | All supported versions of FortiOS. |
Solution |
Allowing SSL VPN users over IPsec is easily achievable by referring to SSL VPN to IPsec VPN - FortiGate administration guide.
Sometimes, the Remote side accepts traffic only from certain IP addresses.
Consider the following example:
192.168.15.2------FGT(local)-----172.16.1.1----===IPsec====-----FGT(remote)---- 192.168.16.2
There are two methods to achieve this, and both are explained in Technical Tip: Implement Source-NAT for IPsec interface.
In this particular scenario, where the SSL VPN subnet needs access to the resource across the other side of the tunnel, the configuration must be set up differently than in the method explained above.
Follow these steps to allow access:
Note: In this example, there is no need to specify the selector of the SSL VPN under IPsec Phase-2, as that configuration was taken care of by the IP pool.
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.