Created on 
    
	
		
		
		07-24-2025
	
		
		07:39 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
  Edited on 
    
	
		
		
		08-04-2025
	
		
		05:51 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 By  
				
		 Jean-Philippe_P
		
			Jean-Philippe_P
		
		
		
		
		
		
		
		
	
			 
		
| Description | This article describes that the firewall address (enabled as the destination address on sslvpn firewall policy) is injected into the FortiClient after a successful SSL VPN connection. | 
| Scope | FortiGate. | 
| Solution | In some FortiOS versions, the following sslvpn debug command shows the firewall address enabled on the SSL VPN firewall policy, which is injected into the FortiClient once the user is successfully connected to the SSL VPN. 
 diagnose debug disable diagnose vpn ssl debug-filter src-addr4 x.x.x.x <----- Public IP of the endpoint. 
 In this example, the firewall address 4.2.2.2/32 enabled as the destination address on firewall policy ID 321 is supposed to be injected into the FortiClient: 
 The firewall address is created: 
 config firewall address 
 The option 'Enabled Based on Policy Destination' is enabled on the SSL VPN portal: 
 config vpn ssl web portal 
 The SSL VPN setting is properly configured: 
 config vpn ssl settings 
 The created firewall address is enabled as the destination address on the policy: 
 config firewall policy After the user is connected to the SSL VPN, it is seen from the debug output that the destination address of the SSL VPN policy is injected into the FortiClient after the SSL VPN is connected to the VPN: 
 2025-07-18 12:19:38 [3948:root:19a1]deconstruct_session_id:492 decode session id ok, user=[tester], group=[VPN_Users],authserver=[],portal=[Navan_POC],host[95.3.2.38], saml_logout_url=yes,pip=95.3.2.38,grp_info=[LPrCLl],rmt_grp_info=[kEH3Pl] 
 Here is the screenshot from the routes on user's PC after VPN connection: 
 
 On Linux, the command is usually 'ip route'. Here is an example of this output on Ubuntu: 
 
 Related articles: Technical Tip: Access to Specific FQDN using Split Tunnel SSL VPN | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.