Created on
07-24-2025
07:39 AM
Edited on
08-04-2025
05:51 AM
By
Jean-Philippe_P
Description | This article describes that the firewall address (enabled as the destination address on sslvpn firewall policy) is injected into the FortiClient after a successful SSL VPN connection. |
Scope | FortiGate. |
Solution |
In some FortiOS versions, the following sslvpn debug command shows the firewall address enabled on the SSL VPN firewall policy, which is injected into the FortiClient once the user is successfully connected to the SSL VPN.
diagnose debug disable diagnose vpn ssl debug-filter src-addr4 x.x.x.x <----- Public IP of the endpoint.
In this example, the firewall address 4.2.2.2/32 enabled as the destination address on firewall policy ID 321 is supposed to be injected into the FortiClient:
The firewall address is created:
config firewall address
The option 'Enabled Based on Policy Destination' is enabled on the SSL VPN portal:
config vpn ssl web portal
The SSL VPN setting is properly configured:
config vpn ssl settings
The created firewall address is enabled as the destination address on the policy:
config firewall policy After the user is connected to the SSL VPN, it is seen from the debug output that the destination address of the SSL VPN policy is injected into the FortiClient after the SSL VPN is connected to the VPN:
2025-07-18 12:19:38 [3948:root:19a1]deconstruct_session_id:492 decode session id ok, user=[tester], group=[VPN_Users],authserver=[],portal=[Navan_POC],host[95.3.2.38], saml_logout_url=yes,pip=95.3.2.38,grp_info=[LPrCLl],rmt_grp_info=[kEH3Pl]
Here is the screenshot from the routes on user's PC after VPN connection:
On Linux, the command is usually 'ip route'. Here is an example of this output on Ubuntu:
Related articles: Technical Tip: Access to Specific FQDN using Split Tunnel SSL VPN |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.